Dash framework versions before 2.15.0 are vulnerable to Cross-site Scripting (XSS) via href attribute in anchor tags. This template tests for javascript:alert payload injection.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view