T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:42- Finding
Unescaped User Input Allows Active SVG Markup Injection
- Content
View full analysis
" if [[ -n "$label" ]]; then local tx=$(( x + w/2 )) local ty=$(( y + h/2 + 4 )) echo " ${label}" fi } ``` Additional affected sinks include: ```bash svg+=" ${step}?"$'\n' ``` ```bash annotation_block+=" ${num}"$'\n' annotation_block+=" ${label}"$'\n' ``` ```bash annotation_block+=" ${num}. ${label}"$'\n' ``` ### Technical Analysis Values received through options such as `--sections`, `--fields`, `--steps`, and `--notes` are inserted directly into SVG text nodes without XML escaping or sanitization. Characters such as `<`, `>`, and `&` therefore retain their markup semantics. An attacker can terminate the intended `` element and inject additional SVG elements, including scripts or elements containing event-handler attributes. For example, a section label conceptually shaped as the following can escape the text context: ```xml ``` The generated file remains structurally capable of being interpreted as SVG. Whether script executes depends on how the SVG is opened or embedded; direct navigation and active embedding contexts such as `- Remediation
View remediation
` with `>` - `"` with `"` - `'` with `'` 2. Apply escaping to every user-controlled value before inserting it into an SVG text node or attribute, including section names, component fields, flow steps, decision labels, note numbers, and note labels. 3. Keep text-node escaping and attribute-value escaping as separate helper functions so future code cannot accidentally use the wrong output encoding. 4. Consider using an SVG/XML generation library that creates DOM nodes rather than constructing markup through string concatenation. 5. If only plain labels are required, validate inputs against an explicit allowlist of expected characters and reject control characters or markup delimiters. 6. Add regression tests containing `<`, `>`, `&`, quotes, closing tags, event handlers, and `
