{
"path": "/blog/xss-via-indirect-prompt-injection",
"site": "at://did:plc:5fyfskntvw6jltxmdu2we7nw/site.standard.publication/3mdro5atvvd2o",
"tags": [
"security",
"bug bounty"
],
"$type": "site.standard.document",
"title": "Finding XSS via indirect prompt injection",
"bskyPostRef": {
"cid": "bafyreiafsu5vazaqqrwptdvtlikszhqeegbbb3oofiqvnfwrbm25dfxx24",
"uri": "at://did:plc:5fyfskntvw6jltxmdu2we7nw/app.bsky.feed.post/3mif3fae3d42r"
},
"description": "A short writeup of finding a stored XSS vulnerability in an AI powered writing app",
"publishedAt": "2026-03-31T00:00:00.000Z",
"canonicalUrl": "https://quasigod.xyz/blog/xss-via-indirect-prompt-injection"
}