What is XSS in an AI-built app?
Cross-site scripting (XSS) is when text a user or model supplies is rendered as code in someone else's browser, letting an attacker act as that person. Modern frameworks escape output by default, so XSS in AI-built apps usually comes from rendering raw HTML or markdown, and increasingly from displaying AI model output that an attacker influenced through prompt injection.
Where it comes from
- Rendering user content as raw HTML, for example with
dangerouslySetInnerHTMLorv-html. - Markdown renderers that allow HTML.
- AI responses rendered as HTML, containing links or scripts an attacker planted.
- User-supplied URLs in links, including
javascript:URLs.
Prevention
Let the framework escape output; sanitise any HTML you must render with a maintained sanitiser; restrict link schemes to http and https; add a Content-Security-Policy. Treat model output exactly like user input.
How to check your app
Search the code for the places that render raw HTML: dangerouslySetInnerHTML in React, v-html in Vue, innerHTML assignments, and markdown renderers configured to allow HTML. For each, ask where the content comes from. If any part comes from a user, a third party or an AI model, it needs sanitising with a maintained library before it is rendered.
Then try it: enter <img src=x onerror=alert(1)> into profile fields, comments and chat messages, and ask your AI feature to include that text in its answer. If a dialog appears when the content is displayed, the field is vulnerable. Check where other users see your content, such as shared documents or admin screens, because stored XSS that runs in an admin's browser is the most damaging version.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Is XSS still common?
Less than it was, thanks to frameworks. The raw-HTML shortcuts AI tools reach for bring it back.
Can a chatbot cause XSS?
Yes, if its output is rendered as HTML without sanitising.