diff --git a/src/applications/differential/view/revisioncomment/DifferentialRevisionCommentView.php b/src/applications/differential/view/revisioncomment/DifferentialRevisionCommentView.php index 86e81999f7..1d0691d1f9 100644 --- a/src/applications/differential/view/revisioncomment/DifferentialRevisionCommentView.php +++ b/src/applications/differential/view/revisioncomment/DifferentialRevisionCommentView.php @@ -119,7 +119,7 @@ final class DifferentialRevisionCommentView extends AphrontView { $inline_render[] = ''. ''. - $changeset->getFileName(). + phutil_escape_html($changeset->getFileName()). ''. ''; foreach ($inlines as $inline) {