cspshivam/playground
XSS Level 10 / 10 Hard
← All labs

Context — JSON under CSP

Your input is reflected into a JSON blob served under a lax policy. Achieve execution regardless.

Search analytics

The page bootstraps a small config object with your last search term. There is no restrictive Content-Security-Policy on this lab, so inline execution is allowed.

Config not loaded.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.