@puckipedia @gargron in the future its probably better to report security issues privately to a developer. The issue wasn't exactly obvious from the PR—you have to know a fair bit about how ruby blocks work to exploit it (or figure out that the microformats block isn't anchored at the end).