Text becomes code when a browser, shell, or DB parses it
The Chain
Attacker influences input → LLM produces output containing attacker payload → Application passes output to downstream system without sanitization → Downstream system executes the payload. The LLM is the bridge. The missing sanitization is the gap.