XST isn’t about injecting tags into the browser;
the attacker must already be able to do that.
Although XST attacks rely on browser scripting to exploit the vulnerability, the vulnerability is not the injection of JavaScript.
XST is a means for accessing headers normally restricted from JavaScript.