An XSS injection was possible because the sanitization of the Cyrillic character i bypass a protection mechanism against user-inputted HTML elements such as the <script> tag.
{
"url": "https://pkg.go.dev/vuln/GO-2022-0762",
"review_status": "REVIEWED"
}