{
  "path": "/blog/xss-via-indirect-prompt-injection",
  "site": "at://did:plc:5fyfskntvw6jltxmdu2we7nw/site.standard.publication/3mdro5atvvd2o",
  "tags": [
    "security",
    "bug bounty"
  ],
  "$type": "site.standard.document",
  "title": "Finding XSS via indirect prompt injection",
  "bskyPostRef": {
    "cid": "bafyreiafsu5vazaqqrwptdvtlikszhqeegbbb3oofiqvnfwrbm25dfxx24",
    "uri": "at://did:plc:5fyfskntvw6jltxmdu2we7nw/app.bsky.feed.post/3mif3fae3d42r"
  },
  "description": "A short writeup of finding a stored XSS vulnerability in an AI powered writing app",
  "publishedAt": "2026-03-31T00:00:00.000Z",
  "canonicalUrl": "https://quasigod.xyz/blog/xss-via-indirect-prompt-injection"
}