T09 · Insecure Skill Coding Practices
- Location
scripts/dashboard_generator.py:92- Finding
Stored HTML and JavaScript Injection in Generated Dashboards
- Content
View full analysis
\n' f'{c["name"]}\n' f'\n' f' ${c["price"]:,.2f}\n' f' {change_arrow} {abs(c["change_pct"]):.1f}%\n' f' {stock_text}\n' f'\n' f'Deal Score: {ds}/100\n' f'\n' f' Low: ${c["low"]:,.2f}\n' f' Avg: ${c["avg"]:,.2f}\n' f' High: ${c["high"]:,.2f}\n' f'\n' f'\n' ) ``` ```python chart_json = json.dumps(chart_datasets) ``` ```html ` sequence from terminating the surrounding script element. The remainder of the value can then introduce a new script or arbitrary HTML. The direct interpolation into the product card also permits stored markup ...[truncated 1483 chars]- Remediation
View remediation
... ``` ```javascript const chartData = JSON.parse( document.getElementById("chart-data").textContent ); ``` 3. Before embedding JSON in HTML, escape characters that are significant to the HTML parser, including `<`, `>`, and `&`. Also handle U+2028 and U+2029 where relevant. 4. Prefer a templating engine with contextual auto-escaping rather than constructing HTML through f-strings. 5. Add a restrictive Content Security Policy. Where practical, move inline JavaScript into a local static file and prohibit inline scripts. 6. Add regression tests covering names containing: ```text" ' < > & ``` ]]>
