LeafKit 1.14.2 has just been released to address a vulnerability where values of array or dictionary type would not be HTML-escaped when used in Leaf variable substitution tags, allowing XSS injection if the content of those values was at least partially under user control.
More details are available in HTML escaping may be skipped for Collection values, enabling XSS · Advisory · vapor/leaf-kit · GitHub.
Thanks to @iCMDdev / iCMDdev (CMD) · GitHub for reporting this issue!