AI output is the new XSS: This vulnerability stems from trust
Over twenty years ago, when XSS was first proposed, many people's initial reaction was similar to yours and mine today: 'Isn't it just injecting some script into the page? How big a deal can it be?' We all know how things turned out later—almost every website that took user input seriously got taught a hard lesson by this thing. Looking back now, the lesson from those days can be summed up in one sentence: browsers can't distinguish which code is written by the program itself and which is injected by users.
Physix Frontier