Ooo some xss! Confirming I see the alert, I'm curious if you found you were able to properly escape the iframe sandbox however.
o
s