Skip to content

Image: portswigger.net · rights & removal

Executive Summary

A user explored web browser limitations regarding HTML tag naming conventions and event handling to discover methods for bypassing security controls. The exploration began by investigating the behavior of the `localName` property, which revealed a lowercase version of the tag name, suggesting potential avenues for using uppercase JavaScript. Subsequent experimentation involved manipulating tag names with characters like slashes, whitespace, and newlines, noting that line and paragraph separators were treated differently from standard JavaScript newlines. The user discovered that by leveraging specific HTML attributes, such as `part`, they could manipulate event objects to execute code via the `onfocus` event handler. Further testing revealed methods to use elements like `contenteditable` for focusability and to utilize functions like `getAttributeNode` and `setHTMLUnsafe` to achieve further manipulation of the DOM. The findings indicate that seemingly innocuous HTML properties can be exploited to introduce JavaScript payloads or markup, potentially bypassing Web Application Firewalls (WAFs).

Facts Only

* The user investigated allowed characters in HTML tag names, noting they must begin with "a-zA-Z".
* Inspection of the `localName` property revealed a lowercase version of the tag name.
* The method of chaining the `onfocus` event with itself was explored.
* A string value from `attributes[0].value` could be converted into a function using the `new` operator.
* Fuzzing of tag names showed that alphabetic characters, forward slashes, whitespace, and newlines were transformed during mutation.
* Line and paragraph separator characters did not transform as standard JavaScript newlines.
* An opening angle bracket could be included in a tag name to combine with attributes for XSS vectors.
* The `part` attribute was tested, which converts space-separated values into an array, allowing payload injection via the `onfocus(event)` portion of the event handler.
* Using `contenteditable` was discovered as an alternative method to make an element focusable.
* The function `getAttributeNode` and `setHTMLUnsafe` were noted as relevant functions.
* A variant using `classList` was found as an alternative to the `part` attribute vector.

Full Take

The narrative demonstrates a progression from a simple inquiry about technical constraints to advanced exploitation techniques, suggesting that vulnerabilities are often latent within seemingly benign features of browser implementations. The core implication is that the separation between intended structural representation (HTML) and executable logic (JavaScript) is porous, especially when specific properties like `localName`, `part`, and `classList` are examined closely. The transition from discovering a lowercase tag name to chaining events and leveraging object constructors highlights a pattern where minor deviations in parsing rules can be weaponized. This process echoes the principle that system boundaries—like character encoding or event handling—are not absolute barriers but rather systems of negotiable rules. The existence of methods like `setHTMLUnsafe` and undocumented behaviors in property inspection suggests a persistent gap between documented security expectations and actual browser behavior, which malicious actors can exploit for bypass. The lesson here is less about the specific characters and more about establishing cognitive sovereignty by recognizing that default assumptions about web security are often artifacts of convenience rather than fundamental constraints. What unseen rules govern other seemingly harmless properties in complex systems, and how do we build defenses against emergent behaviors rather than static blocklists?

From the original · PortSwigger Research

Published: Tuesday, 25 August 2026 at 14:24 UTC Updated: Tuesday, 25 August 2026 at 14:24 UTC I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that?
Read the full story at portswigger.net

Sentinel — Human

Confidence

This appears to be a human-written exploration documenting a personal technical experiment regarding HTML/JavaScript manipulation, characterized by a highly engaged, step-by-step narrative style.

Signals Detected
low severity: Erratic sentence length and high density of very specific, technical code examples interspersed with reflective commentary.
low severity: The text flows logically as a narrative process of discovery, driven by an internal exploratory mindset rather than a purely objective statement.
low severity: No detectable verbatim repetition or reliance on external quoted expert sources; the structure is idiosyncratic to a personal walkthrough.
severity: The content is highly specific, detailed, and presents a 'personal journey' of technical discovery, which is characteristic of human-generated explanatory content.
Human Indicators
Use of first-person narrative ('I was on my laptop', 'I tried placing', 'I started messing around') creating an idiosyncratic voice.
The text models a specific, chaotic, yet ultimately systematic process of experimentation and discovery rather than a linear argument.