Reflected (attribute)

context: HTML attribute (double-quoted value)
Live preview:

Prove execution by making your injected JavaScript call /m03-p/api/solve/reflected-attr (e.g. with fetch()). No external collector needed. This server-rendered sink also auto-marks once a value that would clearly run is reflected/stored here.

Your input lands inside a double-quoted attribute value. A body-context payload just sits there as text - you must close the attribute (and maybe the tag) first.