Goes back to the same thing we've known for years. You must treat all user input as toxic poison. Do any frameworks take care of this for you automatically? Because it seems like this is the root of most attacks on web apps and I'm wondering why we never seem to learn.