Impact
Based on the description, it is inferred that the vulnerability becomes exploitable when an attacker can supply a template containing consecutive expressions that are rendered by the Go html/template package. The missing reset of context tracking causes subsequent regular expression literals to be misidentified and inadequately escaped, allowing injection of malicious JavaScript into the rendered output. The result is a web‑application‑level injection that can lead to arbitrary code execution in a victim’s browser, compromising confidentiality and integrity.
Affected Systems
Affected systems are all Go standard library html/template users in versions of Go that precede the fix documented in the referenced Go issue trackers. The patch is available in newer releases of Go; any program that compiles with an affected Go version and renders user‑supplied templates is at risk.
Risk and Exploitability
Based on the description, it is inferred that attackers would need to supply a template containing a malicious JavaScript literal—an ability that can arise for template‑driven web applications or command‑line tools. The likely attack vector involves providing a template from an untrusted source that contains consecutive expressions. Once the template is processed, the incorrect escaping can be leveraged for XSS. Although an EPSS score is not available and the vulnerability is not listed in CISA KEV, the nature of the flaw indicates high impact. The lack of EPSS data does not diminish the severity of the flaw, as attackers already have a clear path to exploitation via compromised templates.
OpenCVE Enrichment