Such attacks are interesting, but the CSP part is a red herring to some extent; we had this problem without CSP and the issue is mostly that nobody has any good ideas on how to get rid of this class of attacks without breaking the web:
http://lists.w3.org/Archives/Public/public-webappsec/2014Feb...