World Congress 2026 Europe

Dangerous Reactivity: Why AI Output Is the New XSS

July 9, 2026 14:50 – 15:20 · 30 min Stage 9

What this session covers

Vue developers (amongst others, ofc) know one golden rule: never use v-html on user input. Yet, as we’re integrating Large Language Models (LLMs) into our applications, we often make a fatal mistake. We’re treating AI output as a trusted source. This is fine. Well, not automatically….

Let’s look at OWASP LLM05 and how “Improper Output Handling” affects web security. Therefore, let’s discuss examples of how safe inputs can trick models, leading to vulnerabilities such as XSS and injection attacks. By the end, you’ll learn how to be “professionally pessimistic” for AI. You’ll see how to sanitize LLM data, safely render Markdown, and manage AI-generated content. Let’s approach technology with caution, I look forward to exploring this with you! ❤️

Related talks at this congress

Open session

World Congress 2026 Europe

July 10, 2026 · 09:00–09:30

Stage 11

GenAI Is a Junior Dev With Root Access

Julian Totzek-Hallhuber

Lead Solutions Architect at XBOW

Julian Totzek-Hallhuber
Open session

World Congress 2026 Europe

July 9, 2026 · 15:30–17:30

Room R2 (30 Seats)

Shall we play a Game? LLM Security in Practice

Joseph Katsioloudes

Senior Developer Advocate at GitHub

Joseph Katsioloudes
Open session

World Congress 2026 Europe

July 9, 2026 · 16:50–17:20

Stage 11

AI in Your Browser: Exploring Chrome's Built-In LLM

Daniel Ostrovsky

AI Architect at Payoneer

Daniel Ostrovsky
Open session

World Congress 2026 Europe

July 10, 2026 · 13:40–14:10

Stage 8 - powered by Red Hat

Stop Parsing Strings: Treating LLMs Like Type-Safe Microservices

André Behrens

Senior Solution Architect at Atos

André Behrens
All sessions at this congress