I think this line is HTML injection, but hard to exploit: https://github.com/ClickHouse/adsb.exposed/commit/94bd67c851663b64202bf4cdec258786c422e80f