T09 · Insecure Skill Coding Practices
- Location
scripts/render_card_html.py:291- Finding
Stored JavaScript Injection Through Unsafe Card Data Embedding
- Content
View full analysis
str: payload = json.dumps(card_data, ensure_ascii=False, indent=2) script = "\n" marker = "" if marker in template: return template.replace(marker, script) return template.replace("", script + "") ``` ### Technical Analysis The renderer serializes card data with `json.dumps()` and embeds the resulting JSON directly inside an executable HTML `` is interpreted by the HTML parser as the end of the surrounding script element, even when that sequence occurs inside a JavaScript string literal. An attacker can consequently append a new script element containing arbitrary JavaScript. The share-card schema permits general string values and does not reject HTML script terminators. Schema validation therefore does not prevent this attack. Escaping used for statically rendered fields elsewhere in the renderer does not protect the separate `window.__CARD_DATA__` assignment. Example malicious field value: ```html ``` When the card is rendered, the generated output contains the attacker-controlled script. The vulnerability becomes active when a user opens the generated HTML in a browser. ### Attack Path 1. An attacker supplies or influences a share-card JSON string field, such as `name`, `tagline`, `owner.contact`, or anothe ...[truncated 1303 chars]- Remediation
View remediation
``` Serialize the object after applying HTML-safe escaping, then parse it using: ```javascript const card = JSON.parse(document.getElementById("card-data").textContent); ``` 2. At minimum, escape characters significant to the HTML parser before embedding JSON: ```python payload = json.dumps(card_data, ensure_ascii=False, indent=2) payload = ( payload.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") ) ``` Escaping `<` prevents an attacker-controlled `` sequence from terminating the element. 3. Prefer setting visible content through `textContent` or other safe DOM APIs rather than constructing HTML from card values. 4. Add regression tests covering malicious values in every user-controlled string field. Test payloads should include: ```text
