Host and x-forwarded-proto are attacker-writable and were interpolated raw into the share page's meta attributes. The proto must now be literally http or https, and the host is HTML-escaped like everything else that reaches the head. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>