XSS in Notion Embeds: Common Mistakes and Fixes
Notion embeds feel harmless. Paste a link, get a nice preview, move on. That’s exactly why teams get sloppy with them. I’ve seen engineers treat “embed” as a trusted content type, when it’s really just another path for untrusted input to land in your app. If your product accepts Notion pages, renders Notion-derived HTML, proxies embed URLs, or wraps third-party content in iframes, you’re dealing with XSS risk whether you planned for it or not. ...