XSS Escape — Breaking Out of a Script String Context

Escape a JavaScript string context inside a script tag by injecting a closing script tag that the sanitizer fails to block.

February 28, 2026 · 2 min · giordii