No executable content
Sourcerer (CVE-2026-74253) executed {source} blocks found in rendered HTML, including values reflected from URLs, forms, cookies and headers. This site stores copy as TypeScript modules. The contact form strips tags and {source} blocks before writing a JSON file. Nothing a visitor sends is evaluated as code.