← All labs
XSS Level 10 / 10 Hard

Context — JSON / CSP Bypass

Your input is reflected into a JSON blob under a permissive policy. Achieve execution.

Search analytics

The page bootstraps a small config object with your last search term. There is no restrictive Content-Security-Policy on this lab, so inline execution is allowed.

Config not loaded.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of Uncrypt Playground is not part of the target.