T09 · Insecure Skill Coding Practices
- Location
scripts/html_report.py:31- Finding
Stored HTML and JavaScript Injection in Daily Nutrition Reports
- Content
View full analysis
{meal.get('meal', f'第{i+1}餐')} {meal.get('time', '')}{items_str}``` ### Technical Analysis The report generator directly interpolates `meal`, `time`, `foodName`, and `amount_g` values into an HTML document without HTML escaping or contextual output encoding. Food names can originate from user-provided meal descriptions. In particular, `NutritionCalc.parse_food_items()` preserves the original name for an unknown food, and `NutritionCalc.save_meal()` persists the resulting value in a diary JSON file. Values returned by TianAPI or loaded from cache and diary files are also treated as trusted. For example, an attacker-controlled food or meal name containing the following markup would be rendered as executable HTML rather than text: ```html``` This is a stored injection because the malicious value can be saved in the diary and executed later when the generated report is opened. The affected generated document does not define a Content Security Policy that would prevent inline event-handler execution. ### Attack Path 1. An attacker supplies a crafted food or meal name containing HTML with an inline JavaScript event handler. 2. `parse_food_items()` retains the attacker-controlled value when it cannot safely map it to a built-in food. 3. `sa ...[truncated 1216 chars]
- Remediation
View remediation
``` The policy should be adapted for the report's legitimate resources and should avoid permitting inline scripts or event handlers. 6. Add regression tests using payloads containing `
