Cybersecurity glossary
What is Mutation XSS (mXSS)?
Learn what mutation XSS (mXSS) is, how browser HTML mutations break sanitizer assumptions, where mXSS appears in rich-text pipelines, and how to reduce mutation-based bypass risk.
Definition
Mutation XSS (mXSS) is a class of cross-site scripting where seemingly safe HTML is altered by browser parsing, serialization, or mutation logic—such that a sanitizer’s clean output becomes dangerous after the browser mutates the markup.
Why mXSS matters
Teams often believe “we sanitized, so we are safe.” Mutation XSS (mXSS) targets the gap between sanitizer models and real browser HTML behavior. Markup that looks harmless in a string can be rewritten by parsing, namespace fixes, or serialization into something that executes.
Rich content features—comments, email previews, document editors—are frequent mXSS battlegrounds.
How mutation XSS works
Attacker submits exotic HTML
Payload uses tricky nesting, namespaces, or encoding forms that stress parsers.
Sanitizer evaluates a snapshot
Server or client sanitizer accepts markup that appears inert under its model.
Browser mutates the HTML
Parsing, repair, or round-trip serialization changes structure or semantics.
Dangerous content appears
Scripts, handlers, or executable contexts emerge after mutation.
Victim views the content
The mutated DOM executes in the application origin.
High-risk product surfaces
Rich-text editors
User HTML stored and re-rendered with formatting preserved.
Email / HTML previews
Hostile messages rendered inside webmail-like UI.
Markdown with raw HTML
Optional raw HTML features expand mutation surface.
Copy-serialize-paste pipelines
Multiple parse/serialize cycles amplify mutation bugs.
Defense strategy
| Control | Role |
|---|---|
| Maintained sanitizer | Keep browser-aligned cleaning with active security fixes |
| Minimize HTML capability | Fewer tags/namespaces mean fewer mutation gadgets |
| Sanitize at render | Clean immediately before DOM insertion, not only at save time |
| Prefer text | Avoid HTML entirely when formatting is unnecessary |
| Strict CSP + Trusted Types | Contain fallout if mutated markup still appears |
Checklist
- Inventory every feature that accepts or renders HTML.
- Use a widely maintained sanitizer and keep it patched.
- Sanitize again at render time after storage round-trips.
- Disable obscure namespaces and SVG/MathML if not required.
- Add regression tests from public mXSS research payloads.
- Avoid home-grown regex sanitizers.
- Deploy strict CSP without unsafe-inline where feasible.
- Consider sandboxed separate-origin previews for untrusted HTML.
The practical takeaway
Mutation XSS (mXSS) is XSS that emerges when browsers mutate HTML that sanitizers previously considered safe. It thrives in rich-HTML features with parse/serialize round-trips.
Treat HTML as a hostile language, sanitize with maintained tools at render time, shrink allowed markup, and keep CSP as a backstop—not as proof that mutations cannot hurt you.
Related security terms
Cross-Site Scripting (XSS)
Parent vulnerability class that mXSS belongs to.
DOM-Based XSS
Client-side XSS closely related to browser DOM behavior.
DOM Clobbering
Another browser HTML edge-case technique used in sanitizer bypass chains.
TrustedHTML
Typed HTML sink control that still requires a mutation-aware sanitizer.
Frequently asked questions
What is mXSS in simple terms?
It is XSS that appears after the browser changes HTML that a sanitizer thought was safe—like a clean string that becomes unsafe once parsed again.
Why do sanitizers struggle with mXSS?
Browsers have complex HTML parsing and namespace rules. Sanitizers that do not perfectly match browser mutation behavior can approve markup that later rearranges into executable content.
Where does mXSS show up most?
Rich-text editors, mail HTML rendering, markdown-to-HTML pipelines, and any feature that stores HTML then re-parses it in the DOM.
Is mXSS different from stored XSS?
mXSS is often delivered as stored HTML, but the distinguishing factor is the mutation/round-trip bypass—not merely persistence.
How do you mitigate mXSS?
Use well-maintained sanitizers aligned with browser behavior, minimize HTML features, prefer text, sanitize at render time, keep libraries updated, and add CSP.
Does encoding fix mXSS?
Context-aware encoding helps when you do not need HTML. For required HTML, encoding alone is insufficient; you need robust sanitization.
Can CSP stop mXSS?
A strict CSP can block many script executions even if mutated markup appears, but unsafe-inline or weak policies reduce that protection.
References
Explore authoritative guidance and frameworks related to mutation xss (mxss).
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.