Simon Willison Publishes 'Incident Report: CVE-2026-LGTM' — His Newest Post on Datasette Apps and Custom HTML Inside Datasette
simonwillison.net·low signal
Willison's latest post (June 26), titled 'Incident Report: CVE-2026-LGTM,' is a link/analysis piece touching on Datasette Apps and running custom HTML applications inside Datasette. The tongue-in-cheek 'LGTM' framing points at the security pitfalls of rubber-stamping embedded or AI-generated web apps. It's worth a read for anyone shipping user-authored or AI-generated HTML in a data tool, a pattern Willison has been steadily building out toward Datasette 1.0.