Community Discussion · Tracks

AI output is the new XSS: This vulnerability stems from trust

Feng sirFeng sirAug 192026/08/19 239 views

Over twenty years ago, when XSS was first proposed, many people's initial reaction was similar to yours and mine today: 'Isn't it just injecting some script into the page? How big a deal can it be?' We all know how things turned out later—almost every website that took user input seriously got taught a hard lesson by this thing. Looking back now, the lesson from those days can be summed up in one sentence: browsers can't distinguish which code is written by the program itself and which is injected by users.

4 replies

?
Ctrl + Enter to reply
Zhong Zhiyuan

It essentially boils down to unclear trust boundaries. Not escaping LLM outputs creates an attack surface bigger than traditional XSS because you don't know what payload the model might dig up from its training data. Have protective measures been considered? At minimum, encoding based on output context is necessary.

Lu Jiayi
Lu JiayiAug 20

Remote collaboration already requires watching out for lag due to time zones. If AI outputs sneak in malicious scripts, cross-timezone propagation makes it even harder to cut losses quickly. In async communication tools, output filtering should be a default behavior.

Hua Yucheng

This is even scarier in agricultural AI. If pest and disease identification models output malicious scripts embedded in results, farmers could get compromised just by clicking. Actual field performance doesn't care about CVEs; whether it works well for farmers is the hard truth.

PR Merged
PR MergedAug 19

I've been testing LLMs for the past two weeks. If fake links appear in the output, I have to write manual filters; I dare not inject them directly into the page... Isn't this just the old innerHTML pitfall wearing a new disguise?