diff --git a/server-core/src/main/java/io/onedev/server/web/component/markdown/MarkdownViewer.java b/server-core/src/main/java/io/onedev/server/web/component/markdown/MarkdownViewer.java index ca6bbc9fd4..7d85622ea9 100644 --- a/server-core/src/main/java/io/onedev/server/web/component/markdown/MarkdownViewer.java +++ b/server-core/src/main/java/io/onedev/server/web/component/markdown/MarkdownViewer.java @@ -219,7 +219,7 @@ public class MarkdownViewer extends GenericPanel { User user = OneDev.getInstance(UserManager.class).findByName(referenceId); if (user != null) { String avatarUrl = OneDev.getInstance(AvatarManager.class).getAvatarUrl(user); - String script = String.format("onedev.server.markdown.renderUserTooltip('%s', '%s', '%s')", + String script = String.format("onedev.server.markdown.renderUserTooltip('%s', '%s')", JavaScriptEscape.escapeJavaScript(avatarUrl), JavaScriptEscape.escapeJavaScript(user.getDisplayName())); target.appendJavaScript(script);