HTML should not be interpreted in notifications
When some HTML is written in a message, it appears as `message` in a notification, but the content is interpreted. This can be a security issue.

issue