diff --git a/html/updates.rss.erb b/html/updates.rss.erb
index 4d6c0057..e4a4ec70 100644
--- a/html/updates.rss.erb
+++ b/html/updates.rss.erb
@@ -28,7 +28,7 @@
package.info_url = "#{base_url}##{pkgname}"
%>
-
- <%= package.name %> (<%= package.version %>) --- <%= package.description %>
+ <%= package.name %> (<%= package.version %>) --- <%= ERB::Util.html_escape package.description %>
The <%= package.name %> package in MELPA has been updated to version <%= package.version %>.
<%= package.build_time.rfc822 %>
<%= package.url %>