[{"data":1,"prerenderedAt":66},["ShallowReactive",2],{"talk-en-dangerous-reactivity":3},{"id":4,"title":5,"alt":6,"author":7,"body":10,"canonical":6,"createdAt":47,"description":48,"extension":49,"img":6,"meta":50,"navigation":51,"otherLanguages":52,"path":57,"seo":58,"stem":59,"tags":60,"__hash__":65},"talks_en\u002Ftalks\u002Fdangerous-reactivity.md","Dangerous Reactivity: Why AI Output Is the New XSS",null,{"name":8,"image":9},"Ramona Schwering","https:\u002F\u002Favatars.githubusercontent.com\u002Fu\u002F29896429?s=120&v=4",{"type":11,"value":12,"toc":40},"minimark",[13,18,22,25,29,33,37],[14,15,17],"h2",{"id":16},"abstract","Abstract",[19,20,21],"p",{},"Vue developers know one golden rule: never use v-html on user input. This or something similar is well-known in other frameworks, too. Yet, as we're integrating Large Language Models (LLMs) into our applications, we often make a fatal mistake. We're treating AI output as a trusted source. This is fine, right? Well, not automatically.",[19,23,24],{},"Let's look at OWASP LLM05 and how \"Improper Output Handling\" impacts the security of our components. Therefore, let's discuss examples where safe inputs can trick models, causing vulnerabilities like XSS and injection attacks. By the end, you'll learn how to be \"professionally pessimistic\" for AI. You'll learn how to sanitize LLM data, safely render Markdown, and manage AI-generated content. Join my session to approach technology with caution, I look forward to exploring this with you!",[14,26,28],{"id":27},"slides","Slides",[30,31],"media-grid",{":media":32},"[{\"name\":\"Slides\",\"description\":\"You can find the slides of the talk on speakerdeck\",\"url\":\"https:\u002F\u002Fspeakerdeck.com\u002Fleichteckig\u002Fdangerous-reactivity-why-ai-output-is-the-new-xss-vue\"}]",[14,34,36],{"id":35},"recording","Recording",[30,38],{":media":39},"[{\"name\":\"NDC Copenhagen 2026\",\"url\":\"https:\u002F\u002Fwww.youtube-nocookie.com\u002Fembed\u002F1uhV9yR-WZg\"}]",{"title":41,"searchDepth":42,"depth":42,"links":43},"",2,[44,45,46],{"id":16,"depth":42,"text":17},{"id":27,"depth":42,"text":28},{"id":35,"depth":42,"text":36},"2026-06-03T09:00:00.000Z","Treating LLM output as trusted is the new v-html mistake — OWASP LLM05 and how to safely render AI-generated content.","md",{},true,[53],{"locale":54,"name":55,"path":56},"de","german","\u002Fde\u002Fdangerous-reactivity","\u002Ftalks\u002Fdangerous-reactivity",{"title":5,"description":48},"talks\u002Fdangerous-reactivity",[61,62,63,64],"NDC Copenhagen 2026","WeAreDevelopers World Congress 2026","React Advanced London 2026","SymfonyCon Warsaw 2026","d8wbYPDJVkNtZNnrmtNXlw8nz-01-qBiKoTMYijWxG0",1784632035579]