Bypass Content-Security-Policy to achieve XSS when CSP blocks inline scripts. Covers JSONP gadgets, framework abuse (Angular/HTMX/Alpine), missing directive exploitation, and nonce/hash weaknesses. Use when you have HTML injection but CSP prevents script execution.