1

Requirements: an account with a family plan

  1. Click the "Add Member" button in Settings > Family members
  2. Copy the kagi.com/join link
  3. Modify the family name to "anything <s>"
  4. Open the link (unauthenticated)
  5. The page will have a manipulated DOM

Impact: minor.
The XSS <script> tag is blocked by the inline-src policy, but it can still be used to modify the DOM with other tags.

Here is an example screenshot with an inserted <u> tag:

The name should be sanitized and escaped instead.

    No one is typing