From e342bf765e95abfc7c114a43ae3df6e9e8690ae1 Mon Sep 17 00:00:00 2001 From: Diptanil Saha Date: Mon, 10 Aug 2026 00:44:33 +0530 Subject: [PATCH] fix: escape `customer_details` on lead creation from appointment (#57947) --- erpnext/crm/doctype/appointment/appointment.py | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/erpnext/crm/doctype/appointment/appointment.py b/erpnext/crm/doctype/appointment/appointment.py index da91a73f105..8beed20befa 100644 --- a/erpnext/crm/doctype/appointment/appointment.py +++ b/erpnext/crm/doctype/appointment/appointment.py @@ -13,6 +13,7 @@ from frappe.model.document import Document from frappe.share import add_docshare from frappe.utils import add_to_date, cint, date_diff, get_datetime, get_url, getdate, now, now_datetime from frappe.utils.data import sha256_hash +from frappe.utils.html_utils import escape_html from erpnext.setup.doctype.holiday_list.holiday_list import is_holiday @@ -269,7 +270,11 @@ class Appointment(Document): if self.customer_details: lead.append( "notes", - {"note": self.customer_details, "added_by": frappe.session.user, "added_on": now()}, + { + "note": escape_html(self.customer_details), + "added_by": frappe.session.user, + "added_on": now(), + }, ) self.party = lead.insert(ignore_permissions=True).name