<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I just published a write-up on prototype pollution and how it leads to XSS.]]></title><description><![CDATA[<p>I just published a write-up on prototype pollution and how it leads to XSS.</p><p>The key idea: you’re not injecting into the sink—you’re controlling the property lookup that eventually reaches it.</p><p>Pollute → Gadget → Sink → Execution</p><p>Includes examples and common vulnerable patterns (merge functions, __proto__, etc.)</p><p><a href="https://medium.com/@marduk.i.am/prototype-pollution-15f47d9e5c6a" rel="nofollow noopener"><span>https://</span><span>medium.com/@marduk.i.am/protot</span><span>ype-pollution-15f47d9e5c6a</span></a></p><p><a href="https://infosec.exchange/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/WebSecurity" rel="tag">#<span>WebSecurity</span></a> <a href="https://infosec.exchange/tags/AppSec" rel="tag">#<span>AppSec</span></a> <a href="https://infosec.exchange/tags/Infosec" rel="tag">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/BugBounty" rel="tag">#<span>BugBounty</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/997ca32f-d468-44c1-9076-74ebad644e98/i-just-published-a-write-up-on-prototype-pollution-and-how-it-leads-to-xss.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:11:53 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/997ca32f-d468-44c1-9076-74ebad644e98.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 28 Apr 2026 21:25:49 GMT</pubDate><ttl>60</ttl></channel></rss>