I was reading this Question and Answer here and I am curious what are some dangers that could take place. I imagine that some sort of XSS or CSRF would be the problem, but they would have to have the ability to alter the return of the fetch.
Can someone provide an example for this being a problem and explain how in practice data should be received from a back end source?