Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the constructcopydiv function in copyandpaste.js.