hledger 1.52.3 contains more hledger-web security fixes, for an XSS vulnerability when the add form fails, and a bug allowing include directives to be inserted with only `add` permission. All hledger-web users should upgrade.
A big thanks to Arthur Cinader for helping to find and fix these, in hledger 2.
They're needed in hledger 1 too, so I backported them, as allowed by our latest AI policy. As before, these affect hledger-web; I don't expect to this to arise for hledger or hledger-ui.