2cdae04ddc1e46cdfc2e5e8cf479cbbbb616ad10
chmalee
  Tue Sep 22 15:55:10 2026 -0700
htmlSanitize tooltips before printing them into the page, refs #38226

diff --git src/hg/js/utils.js src/hg/js/utils.js
index 03cb16912fe..53836611633 100644
--- src/hg/js/utils.js
+++ src/hg/js/utils.js
@@ -4039,33 +4039,33 @@
             if (typeof greyBarIcons !== 'undefined' && greyBarIcons === true) {
                 // show the gear icon over the grey bar to bring up the context menu
                 let tdBtn = document.getElementById("td_btn_" + id);
                 if (tdBtn) {
                     let span = document.getElementById("gear_btn_" + id);
                     if (span) {
                         // hide any gears that may be present from dragging
                         $(document.querySelectorAll("[id^=gear_btn]")).hide();
                         $(span).show();
                         if (!span.dataset.alreadySetup) {
                             tdBtn.style.position = "relative";
                             let tdbKey = tdBtn.id.replace("td_btn_","");
                             let tdb = hgTracks.trackDb[tdbKey];
                             let tooltip = " click or right click to configure... drag to reorder";
                             if (typeof tdb.parentLabel !== 'undefined') {
-                                addMouseover(span, tdb.parentLabel + tooltip + " highlighted subtracks");
+                                addMouseover(span, htmlEncode(tdb.parentLabel + tooltip + " highlighted subtracks"));
                             } else {
-                                addMouseover(span, tdb.shortLabel + tooltip);
+                                addMouseover(span, htmlEncode(tdb.shortLabel + tooltip));
                             }
                             span.addEventListener("click", (e) => {
                                 // trigger a click on the <a> of the td
                                 e.preventDefault();
                                 e.stopPropagation();
                                 e.stopImmediatePropagation();
                                 const clickEvent = new MouseEvent("click", {
                                     bubbles: true,
                                     cancelable: true,
                                     view: window,
                                     clientX: tdBtn.getBoundingClientRect().left + 15,
                                     clientY: tdBtn.getBoundingClientRect().top,
                                     button: 1,
                                 });
                                 tdBtn.children[0].dispatchEvent(clickEvent);