T09 · Insecure Skill Coding Practices
- Location
scripts/dashboard.html:798- Finding
Remote News Content Is Rendered Through Unsafe innerHTML
- Content
View full analysis
``).join(''); ``` ### Technical Analysis The dashboard interpolates news properties directly into an HTML template and assigns the result to `innerHTML`. The properties `title`, `source`, `pub_time`, `sentiment`, and `url` originate from external Eastmoney, Sina, or CLS responses and are not HTML-escaped before rendering. Because `innerHTML` invokes the browser's HTML parser, a malicious or compromised news provider can supply markup containing event handlers or other executable HTML. The `url` property is also placed directly ...[truncated 1895 chars]${n.title} ${n.sentiment}📰 ${n.source} 🕐 ${n.pub_time} ${n.sentiment_score ? `得分: ${n.sentiment_score}` : ''}${n.url ? `查看详情 →` : ''}- Remediation
View remediation
