... t, err := template.New("foo").Parse(`{{define "T"}}Hello, {{.}}!{{end}}`) err = t.ExecuteTemplate(out, "T", "<script>alert('you have been pwned')</ script>") Hello, <script>alert('you have been pwned')</script>! import "html/template" ... t, err := template.New("foo").Parse(`{{define "T"}}Hello, {{.}}!{{end}}`) err = t.ExecuteTemplate(out, "T", "<script>alert('you have been pwned')</ script>") Hello, <script>alert('you have been pwned')</script>! <UFYUUFNQMBUFͷ߹> <IUNMUFNQMBUFͷ߹>