Direct Template Variable Embedding in Script Tags
Template variables like {{ user.name }} or <%= value %> embedded directly into JavaScript code within <script> tags. HTML escaping is applied when JavaScript-specific encoding is required, allowing attackers to break out of strings and inject malicious code through quotes, newlines, or script tags.