CSP bypass via CloudFlare resources + 'unsafe-eval'
go (Chrome/Safari only)
Update: This seems to have been a known trick.
@cgvwzq
🙇
XSS Payload: