Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
https://security.netapp.com/advisory/ntap-20241213-0005/
https://pkg.go.dev/vuln/GO-2023-1753
https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU