← All labs
AI Sec Level 5 / 10 Hard

Insecure Output Handling

The app renders the model's answer as HTML. Turn a reply into XSS.

Assistant with rich replies

This chat renders the assistant's answer as formatted HTML so links and styling look nice. The assistant tends to quote what you said. Turn a reply into script execution.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of Uncrypt Playground is not part of the target.