Skip to content

Rule · AI search

JSON-LD contains a literal </script or <!--

geo/jsonld-unsafeerrorvoid geoupdated

Why it matters

User or CMS content containing </script> ends the script element early; that breaks the JSON and is an XSS vector. The Next.js JSON-LD guide requires escaping <.

How to fix it

Serialize with JSON.stringify(data).replace(/</g, '\u003c') and use a native <script>, not next/script.

Example

tsx
// components/json-ld.tsx (Server Component). JSON.stringify doesn't escape "<", so a string containing
// </script> would break out of the tag; replace it with the JSON escape \u003c.
import type { Graph, Thing, WithContext } from 'schema-dts'

export function JsonLd({ data }: { data: WithContext<Thing> | Graph }) {
  return (
    <script
      type="application/ld+json"
      dangerouslySetInnerHTML={{ __html: JSON.stringify(data).replace(/</g, '\\u003c') }}
    />
  )
}

References

void geo reports 41 rules in this category. Generative-engine optimisation: whether AI crawlers that don't run JavaScript see the same content, valid and visible JSON-LD, an explicit AI robots policy, llms.txt, Markdown mirrors and answer-first writing.