JSFiddle - React, Tailwind, and code Playground

HTML

<script>
    function onSuccess() {
        var response = "<script>alert(1);</\script>";
        document.getElementById("xxx").innerHTML = response;
    }
</script>
<div id="xxx">existing text</div>
<button id="click" onclick="onSuccess();">click</button>

JavaScript

watchNodeForScripts(document.getElementById("xxx"));

function watchNodeForScripts(scriptRecipient) {
    if ('MutationObserver' in window) {
        // Prefer MutationObserver: https://developer.mozilla.org/en-US/docs/Web/API/MutationObserver
        watchUsingMutationObserver();
    } else {
        // Fallback to Mutation Events: https://developer.mozilla.org/en-US/docs/Web/Guide/API/DOM/Events/Mutation_events
        watchUsingDeprecatedMutationEvents();
    }

    function watchUsingMutationObserver() {
        var observer = new MutationObserver(function (mutations) {
            mutations.forEach(function (mutation) {
                var i, addedNodes = mutation.addedNodes;

                for (i = 0; i < addedNodes.length; i++) {
                    handleAddedNode(addedNodes[i]);
                }
            });
        });

        observer.observe(scriptRecipient, {
            childList: true
        });
    }

    function watchUsingDeprecatedMutationEvents() {
        scriptRecipient.addEventListener("DOMNodeInserted", function (event) {
            handleAddedNode(event.target);
        });
    }

    function handleAddedNode(node) {
        // Don't try to execute non-script elements
        if (!(node instanceof HTMLScriptElement)) return;

        // Don't try to execute linked scripts
        if (node.src !== "") return;

        // Use 'new Function' instead of eval to avoid
        // the creation of a (undesired) closure
        fn = new Function(node.textContent);
        fn.call(window);
    }
}