From 0ac23788f185e7a177d04f2f401966a83450d57d Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 6 Jun 2026 19:21:50 +0200 Subject: [PATCH] Escape voice-derived attributes in Azure TTS SSML The Azure TTS handler (_tts_azure) interpolated the user-supplied voice, and the locale derived from it, into the SSML xml:lang and attributes without XML-escaping, while the text body was already escaped (2e75c6dbd). Escape both attributes too, so every user-derived value in the SSML document is consistently encoded. Co-authored-by: alanturing881 Co-Authored-By: Claude Opus 4.8 (1M context) --- backend/open_webui/routers/audio.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/open_webui/routers/audio.py b/backend/open_webui/routers/audio.py index 441915972d..38408c0387 100644 --- a/backend/open_webui/routers/audio.py +++ b/backend/open_webui/routers/audio.py @@ -467,8 +467,8 @@ async def _tts_azure(request, payload, file_path, file_body_path, user): output_format = request.app.state.config.TTS_AZURE_SPEECH_OUTPUT_FORMAT ssml = ( - f'' - f'{html.escape(payload["input"])}' + f'' + f'{html.escape(payload["input"])}' f'' )