mirror of https://github.com/bitcoin/bitcoin
Currently, error messages (such as InitError) are displayed as-is, which means Qt does auto detection on the format. This means that it's possible to inject HTML from the command line though e.g. specifying a wallet name with HTML in it. This isn't a direct security risk because fetching content from internet is disabled (and as far as I know we never report strings received from the network this way). However, it can be confusing. So explicitly force the format as text.pull/12617/head
parent
9903537750
commit
6fbc0986fa
Loading…
Reference in new issue