The contents of the ‘file’ in this code
are a single Markdown cell in ipynb
format. Because Markdown allows
arbitrary HTML, in trusted mode, we can
inject any HTML code we want into the
webview.
This is a very common foot-gun with markdown. Unfortunate that they did not sanitize the HTML output from their renderer.