If a trusted template author were to write a <script> tag...
Moderate severity
Unreviewed
Published
May 7, 2026
to the GitHub Advisory Database
•
Updated May 13, 2026
Description
Published by the National Vulnerability Database
May 7, 2026
Published to the GitHub Advisory Database
May 7, 2026
Last updated
May 13, 2026
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block.
References