> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://ctd7toue00jc.s.dav3n.casa/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://ctd7toue00jc.s.dav3n.casa/_mcp/server.

# Proof of Concept

> WB16 attacker-authored page served from launchdarkly.com — unique marker WB16-ATTACKER-AUTHORED-7f3a9c

# Proof of Concept (attacker-authored)

This page was authored by an external security researcher and is being served
from launchdarkly.com via a Fern docs tenant the researcher registered.

Unique marker: WB16-ATTACKER-AUTHORED-7f3a9c

Every byte of this document, including this line, originates from infrastructure
controlled by the researcher — proving full attacker authorship of content
stored and served by the LaunchDarkly apex origin.

[Attacker asset file](./assets/poc.txt)

![poc](/_fern-files/wb19probe.docs.buildwithfern.com/fcbd1286a13741ef7f28f8462347a075b1cd38b8a2fbe43b3e50825305f3a5b0/pages/assets/poc.txt)

[Attacker HTML asset](./assets/poc.html)

[md artifact](./assets/payload.md) · [json artifact](./assets/payload.json)

![poc2](/_fern-img/b66f3d4cec112ca5ddc32e963d80ab4b757fcc7903726dbc68f228791c480c22.webp) ![svg](/_fern-files/wb19probe.docs.buildwithfern.com/6693eb466ab6e820c8183dfde08212d280e612e62cb53244f4465582765b6b96/pages/assets/poc2.svg) [js](./assets/poc2.js) [css](./assets/poc2.css) [xml](./assets/poc2.xml) [csv](./assets/poc2.csv)

[fresh probe](./assets/poc3.txt)

[instance2 probe](./assets/poc4.txt)

![xss](/_fern-files/wb19probe.docs.buildwithfern.com/117e618c002e68f883c3b703ea6d7b6795f6c8f2a137af87401ad52ab61a4131/pages/assets/xss.svg)

[xss html asset](./assets/xss.html)

[wb20 svg xss poc](./assets/poc5.svg)

![xss2](/_fern-files/wb19probe.docs.buildwithfern.com/d3242f59aee0a34f2ed3f699426ae157e07ccc3526edef5fba0e75a580b5bf51/pages/assets/xss2.svg)