T03 · Remote Payload Retrieval and Execution
- Location
templates/shanghai-weather.html:6- Finding
Mutable Third-Party JavaScript Is Retrieved and Executed During Rendering
- Content
View full analysis
``` The Skill instructions also explicitly prescribe this pattern: ```html ``` ### Technical Analysis The templates execute JavaScript retrieved from third-party CDNs whenever Playwright renders a card. The Tailwind URL is unversioned, while the Alpine URL uses the mutable `3.x.x` version range. Neither script has a Subresource Integrity hash. Consequently, the effective executable payload is not fixed to the package version that was audited. A CDN compromise, account compromise, DNS or network-layer redirection under a compromised trust chain, or malicious update to a mutable CDN alias could cause different JavaScript to execute during a later render. The downloaded scripts run in the rendered page and can read its DOM, including any information embedded in a generated card. They can also make outbound network requests because the renderer does not restrict br ...[truncated 1432 chars]- Remediation
View remediation
