fix low-impact XSS