Mutation XSS (mXSS): How the Browser's Parser Rewrites Your Sanitized HTML
Mutation XSS turns HTML that is inert as a string into executable markup the moment the browser parses and re-serializes it. Here is why an innerHTML round-trip defeats a sanitizer, the parser quirks that cause it, and how to stop re-parsing sanitized output.