June 24, 2026

The Bouncer Who Frisked Everyone and Forgot to Lock the Door

A changelog widget’s HTML sanitizer strips every XSS vector you can name — and then hands you a full-page iframe on its own trusted domain…

By anshh.bohara

6 min read