T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:88- Finding
Unescaped User Input Allows HTML and Script Injection in Generated Pages
- Content
View full analysis
" echo ''$2''$2'
'$3'
' } ``` ### Technical Analysis The `create` command places the values of `$2` and `$3` directly into HTML element and attribute contexts without HTML encoding or input validation. An attacker can supply HTML closing tags, new elements, event handlers, or ```` 2. `cmd_create` concatenates the payload directly into the HTML document without contextual encoding. 3. A user or automation process redirects the generated output into an `.html` file. 4. The resulting file is ...[truncated 877 chars]
- Remediation
View remediation
`, `"`, and `'`. 2. Use the local variables rather than positional parameters after validation. 3. Keep every shell variable expansion quoted and use `printf` instead of concatenating unquoted values with `echo`. 4. Correct the argument indexing so the handler consumes `$1` as the title and `$2` as the description after dispatch performs `shift`. 5. If rich HTML is intentionally supported, sanitize it with a well-maintained allowlist-based HTML sanitizer rather than accepting arbitrary markup. 6. Add tests covering closing tags, script elements, event-handler attributes, quotes, ampersands, whitespace, wildcard characters, and missing arguments. A safer structure would be: ```bash html_escape() { local value=$1 value=${value//&/&} value=${value///>} value=${value//\"/"} value=${value//\'/'} printf '%s' "$value" } cmd_create() { local title="${1:-}" local description="${2:-}" [ -n "$title" ] && [ -n "$description" ] || die "Usage: $SCRIPT_NAME create <description>" local safe_title safe_description safe_title=$(html_escape "$title") safe_description=$(html_escape "$description") printf '%s\n' \ "<!DOCTYPE html><html><head><title>${safe_title}${safe_title}
${safe_description}
" } ``` ]]>
