Attacker origin:
XSS target: apollo-composite.uipath.com (UiPath Apollo design system Storybook, shared infrastructure)
Impacted asset: staging.uipath.com — cookie tossing + PII theft via shared .uipath.com domain cookies
Framework: Stencil web components — forceRemount required to rebuild shadow DOM
CSP: None on Storybook — fetch() to external servers works
Interaction: One click — click the "Link" text inside the popup
Sink: ap-link component's href prop → <a href="..."> inside shadow DOM