It looks like the website assumed input from the browser was trusty enough to use it as email content 🤐