JavaScript has been around for almost 30 years and we are still finding ways to hurt ourselves with it.
Sit back, relax, and join me on this journey through the history of JS security vulnerabilities. We will be starting in the days of innerHTML abuse and Cross-Site Request Forgery, moving along through the JSON hijacking era, making a stop to take a look at npm supply chain abuse, and landing in what we’re all dealing with presently: how AI assisted coding is introducing new vulnerabilities in ways we have not had to deal with before.
By the end, you’ll have a better understanding of how JS’s attack surface has evolved, why bugs keep resurfacing under new names (cough cough, it’s trust), and what patterns to watch out for with current code you’re shipping. You’ll also understand why XSS has always been a top OWASP injection vulnerability, and will continue to be until we enforce better security practices.
You don't need a security background to follow along, you just need to have run npm install and trusted what came back.
This talk has been presented at JSNation US 2026, check out the latest edition of this JavaScript Conference.






















