T08 · Insecure Dependencies
- Location
scripts/html_report.py:194- Finding
Mutable Remote JavaScript Is Executed in Weekly Reports
- Content
View full analysis
``` ### Technical Analysis Generated weekly reports retrieve and execute Chart.js from a public CDN whenever the report is opened. The dependency uses the broad `@4` version selector rather than an immutable, exact version, and the script tag does not provide a Subresource Integrity (`integrity`) hash. Consequently, the JavaScript executed by an already-generated report can change after the skill has been audited. A compromised CDN, compromised upstream package release, or unexpected dependency update could cause attacker-controlled JavaScript to execute in the report viewer. The generated page also lacks a restrictive Content Security Policy, so a compromised dependency would be able to initiate outbound requests and manipulate all content in the report. ### Attack Path 1. A user generates a weekly exercise report. 2. The user opens the generated HTML document in a browser or preview component. 3. The report requests `https://cdn.jsdelivr.net/npm/chart.js@4`. 4. The CDN resolves the mutable version selector and returns JavaScript. 5. If the CDN response or selected upstream release has been compromised, the browser executes the malicious JavaScript. 6. The script can read and modify report content and transmit information accessible within the report's browser context to an external server. ### Impact Assessment Successful exploitation provides arbitrary JavaScript execution in the security context of the generated report. An attacker could: - Read exercise and health information rendered in the report. - Alter report statistics or safety advice. - Display phishing or deceptive user-interface elements. - Make outbound network requests and exfiltrat ...[truncated 252 chars]- Remediation
View remediation
``` 4. Verify the hash against the exact reviewed artifact before release. 5. Add a restrictive Content Security Policy. If the dependency is bundled locally, a suitable baseline is: ```html ``` 6. Maintain an inventory of bundled third-party components and periodically review them for known vulnerabilities. ]]>
