Improper sanitization and filtering of HTML entities in user input can lead to cross-site scripting (XSS) attacks where arbitrary JavaScript code is executed in the browser.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1597" }