Injection attack that executes untrusted scripts in a user’s browser, a key risk for dapps that render user provided NFT metadata or markdown without sanitization. ← Fair Launch