diff --git a/kallithea/lib/markup_renderer.py b/kallithea/lib/markup_renderer.py --- a/kallithea/lib/markup_renderer.py +++ b/kallithea/lib/markup_renderer.py @@ -124,7 +124,19 @@ class MarkupRenderer(object): renderer = self._detect_renderer(source, filename) readme_data = renderer(source) - return readme_data + # Allow most HTML, while preventing XSS issues: + # no