T09 · Insecure Skill Coding Practices
- Location
scripts/buildup.py:164- Finding
Stored HTML Injection Through an Unescaped Diagram Filename
- Content
View full analysis
{title} ...{title}
``` The untrusted title originates from the input filename and is written to the generated HTML: ```python title = os.path.splitext(os.path.basename(args.file))[0] + " — build-up" with open(out, "w", encoding="utf-8") as f: f.write(build_html(frames, title)) ``` ### Technical Analysis The basename of the user-selected `.drawio` file is treated as trusted HTML. It is interpolated directly into both the `` element and, more importantly, the `<h1>` element without HTML escaping. On platforms that allow angle brackets and other HTML-significant characters in filenames, such as common Unix filesystems, a filename can contain an event-bearing element such as: ```text <img src=x onerror=alert(document.domain)>.drawio ``` When `buildup.py` processes this file, the resulting heading contains executable HTML: ```html <header><h1><img src=x onerror=alert(document.domain)> — build-up</h1></header> ``` The image load fails and invokes the attacker-controlled event handler when the generated HTML is opened. Escaping the JSON payload does not mitigate this issue because the vulnerable value is independently interpolated into HTML markup. ### Attack Path 1. An attacker creates or ...[truncated 1183 chars]- Remediation
View remediation
{safe_title} ...{safe_title}
``` 4. Keep the original unescaped value only for non-HTML processing where necessary. 5. Add regression tests with filenames containing HTML metacharacters and event-bearing markup, including: ```text.drawio ``` 6. Assert that the generated output contains escaped text such as `<img` and does not contain an executable `
` element. 7. Consider a shared HTML-template helper that performs context-appropriate escaping by default, reducing the chance of similar errors in future generators. ]]>
