diff --git a/addons/mail/static/src/js/composer.js b/addons/mail/static/src/js/composer.js
index 4112a8498cf..2965ccf9298 100644
--- a/addons/mail/static/src/js/composer.js
+++ b/addons/mail/static/src/js/composer.js
@@ -398,7 +398,7 @@ var Composer = Widget.extend({
preprocess_message: function () {
// Return a deferred as this function is extended with asynchronous
// behavior for the chatter composer
- var value = this.$input.val().replace(/\n|\r/g, '
');
+ var value = _.escape(this.$input.val()).replace(/\n|\r/g, '
');
return $.when({
content: this.mention_manager.generate_links(value),
attachment_ids: _.pluck(this.get('attachment_ids'), 'id'),
diff --git a/addons/mail/static/src/js/window_manager.js b/addons/mail/static/src/js/window_manager.js
index fe60dff4bd5..f217d929c20 100644
--- a/addons/mail/static/src/js/window_manager.js
+++ b/addons/mail/static/src/js/window_manager.js
@@ -38,6 +38,7 @@ function open_chat (session) {
});
chat_session.window.on("post_message", null, function (message, channel_id) {
+ message.content = _.escape(message.content);
chat_manager.post_message(message, {channel_id: channel_id});
});
chat_session.window.on("messages_read", null, function () {