Vitess allows HTML injection in /debug/querylogz & /debug/env
The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will.