Good point - will add something on that soon. I by no means am a professional programmer, just a hobbyist sharing what I've learned.
In fact this is caused by using jQuery, which (inexcusably) runs embedded scripts when adding HTML to the page. The simplest solution to this entire class of bugs is simply to not use jQuery and use the better-designed DOM methods instead, which is probably a more modern approach anyway.
Using innerHTML would solve the script injection, but you probably want to use innerText or createTextNode instead, since supporting HTML tags in a basic chat app seems more bug than feature.
The server side should be safe already as it looks like there’s no persistence.