Week 4: Insecure Output Handling — From Toy Demo to Real Attack Chains

Building a toy XSS demo to understand why LLM output shouldn’t be trusted downstream, then tracing how this plays out in real CVEs and NVR-style natural language query systems.

August 10, 2026 · 3 min · 576 words · Lynne Lin