From ce25b8bfab2802098c1e6b2e3c7b0db90f90d556 Mon Sep 17 00:00:00 2001 From: Prathamesh Penshanwar <128643250+PRATHAM777P@users.noreply.github.com> Date: Mon, 27 Apr 2026 23:45:28 +0530 Subject: [PATCH] Potential fix for code scanning alert no. 4: Double escaping or unescaping Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- src/tools/fetch/web-fetch-utils.ts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/tools/fetch/web-fetch-utils.ts b/src/tools/fetch/web-fetch-utils.ts index 39448c1..685555e 100644 --- a/src/tools/fetch/web-fetch-utils.ts +++ b/src/tools/fetch/web-fetch-utils.ts @@ -3,13 +3,13 @@ export type ExtractMode = "markdown" | "text"; function decodeEntities(value: string): string { return value .replace(/ /gi, " ") - .replace(/&/gi, "&") .replace(/"/gi, '"') .replace(/'/gi, "'") .replace(/</gi, "<") .replace(/>/gi, ">") .replace(/&#x([0-9a-f]+);/gi, (_, hex) => String.fromCharCode(Number.parseInt(hex, 16))) - .replace(/&#(\d+);/gi, (_, dec) => String.fromCharCode(Number.parseInt(dec, 10))); + .replace(/&#(\d+);/gi, (_, dec) => String.fromCharCode(Number.parseInt(dec, 10))) + .replace(/&/gi, "&"); } function stripTags(value: string): string {