Hacker News new | ask | show | jobs
by kwamenum86 5479 days ago
"And where does the "huge security hole" come from"

eval'ing a response from a third party essentially runs their code in your context. JSON.parse does not.