cgi.escape is unsafe (quote=False by default) and deprecated in Python 3. We already have an openerp.tools.misc.html_escape version which forwards to the (modern and safe) werkzeug.utils.escape, just use that everywhere, and convert extant uses of werkzeug.utils.escape to utils.html_escape as well so that we do the same thing everywhere.