cross-posted from: lemmy.zip/post/54305624

Open source React executes malicious code with malformed HTML—no authentication needed.