Shared Messaging

Chat App

The room feed renders raw message HTML and accidentally shows messages from other rooms in the default view.

Expected Findings

  • Stored XSS via message content.
  • Cross-room message leakage in the default feed.

Signals

Validation
if (message.length > 0) send(message)