T09 · Insecure Skill Coding Practices
- Location
scripts/report_html.py:75- Finding
Stored HTML and Script Injection Through Remote Announcement Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/report_html.py:75-117
Vulnerability Type: Stored HTML injection / local report XSS
Risk Level: HighComplete Code Snippet
python title = item.get("title", "") rid = item.get("id", "") url = item.get("url", "") reason = item.get("reason", "") entity = item.get("assigned_entity_name", item.get("assigned_entity", "")) caps = item.get("matched_capabilities", []) region_info = item.get("region_info", {}) is_priority = region_info.get("is_priority", False) region = region_info.get("region", "") source = item.get("source", "") publish_time = item.get("publish_time", "") priority_badge = '<span class="badge priority">重点</span>' if is_priority else "" region_badge = f'<span class="badge region">{region}</span>' if region else "" source_badge = f'<span class="badge source">{source}</span>' if source else "" entity_badge = f'<span class="badge entity">{entity}</span>' if entity else "" score_badge = "" if verdict == "investable": sc = item.get("score") lvl = item.get("score_level", "") if isinstance(sc, int): score_badge = f'<span class="badge score">🔥 {lvl} {sc}</span>' caps_html = '<div class="caps">' + "".join( f'<span class="cap-tag">{c}</span>' for c in caps ) + '</div>' if caps else "" link_html = ( f'<a href="{url}" target="_blank" class="detail-link">查看详情</a>' if url else "" ) items_html += f""" <div class="item-card" style="border-left-color: {style['color']}; background: {style['bg']}"> <div class="item-header"> <span class="seq-num">#{seq}</span> <span class="verdict-badge" style="background: {style['color']}; color: white;">{style['label']}</span> {priority_badge}{region_badge}{source_badge}{entity_badge}{score_badge} </div> <div class="item-title">{title}</div> <div class="item-reason">{reason}</div> {caps_html} <div class="item-meta"> <span>ID: {rid}</span> {f'<span>发布时间: {publish_time}</span ...[truncated 3590 chars]- Remediation
View remediation
Remediation Suggestions
- Encode every untrusted value according to its output context:
- Apply
html.escape(value, quote=True)to text and attribute values. - Do not reuse values encoded for text nodes in URL or JavaScript contexts.
- Apply
- Validate links before rendering:
- Parse URLs with
urllib.parse.urlsplit. - Allow only explicitly supported schemes such as
httpsand, if required,http. - Reject control characters, protocol-relative URLs where inappropriate, and schemes such as
javascript,data, andfile.
- Parse URLs with
- Prefer structured rendering helpers rather than manually concatenating HTML strings.
- Add a restrictive Content Security Policy to the generated report, for example:
html <meta http-equiv="Content-Security-Policy" content="default-src 'none'; style-src 'unsafe-inline'; img-src data: https:; base-uri 'none'; form-action 'none'"> - Add
rel="noopener noreferrer"to links usingtarget="_blank". - Add regression tests containing hostile values in every remotely sourced field, including:
- HTML elements and event-handler attributes.
- Quotes that attempt to escape
href. javascript:anddata:URLs.- Encoded and mixed-case unsafe schemes.
- Encode every untrusted value according to its output context:
