Cross-site scripting (XSS) vulnerability detected.
- Rule ID: javascript_express_cross_site_scripting
- Languages: javascript
- Source: cross_site_scripting.yml
Description
Sending unsanitized user input in a response puts your application at risk of cross-site scripting attacks.
Remediations
❌ Avoid including user input directly in a response:
res.send(req.body.data)