https://worldofsoftware.org/why-react-didnt-kill-xss-the-new-javascript-injection-playbook/
Why React Didn’t Kill XSS: The New JavaScript Injection Playbook