diff --git a/static/js/popover_menus.js b/static/js/popover_menus.js index 0da6126faa..0cccbfadcc 100644 --- a/static/js/popover_menus.js +++ b/static/js/popover_menus.js @@ -59,6 +59,8 @@ const default_popover_props = { its CSS to support Zulip's dark theme. */ theme: "light-border", touch: true, + /* Don't use allow-HTML here since it is unsafe. Instead, use `parse_html` + to generate the required html */ }; export function any_active() {