T08 · Insecure Dependencies
- Location
templates/viewer.html:21- Finding
Third-Party JavaScript Loaded Without Subresource Integrity
- Content
View full analysis
Vulnerability Details
File Location:
templates/viewer.html, line 21
Vulnerability Type: Unprotected third-party executable dependency
Risk Level: MediumComplete Code Snippet:
html <script src="https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js"></script>Technical Analysis
The HTML template loads executable p5.js code from a third-party CDN at runtime without a Subresource Integrity (
integrity) attribute. Although the dependency is pinned to version1.7.0and retrieved over HTTPS from a reputable CDN, the browser does not verify that the response matches a cryptographically approved artifact.Consequently, the code ultimately executed by artifacts generated from this template can differ from the code present during the static audit. A compromise affecting the CDN asset or its delivery could cause attacker-controlled JavaScript to execute in the artifact's browser context.
This external dependency also conflicts with the Skill's description of the resulting HTML artifact as completely self-contained.
Attack Path
- A user creates or receives an HTML artifact derived from
templates/viewer.html. - The user opens the artifact in a browser while connected to the network.
- The browser requests
p5.min.jsfrom cdnjs. - An attacker who has compromised the hosted asset or its delivery supplies a modified response.
- Because no integrity hash is specified, the browser accepts and executes the modified JavaScript.
- The malicious script operates with the same browser-page privileges as the legitimate p5.js library.
Impact Assessment
Successful exploitation permits arbitrary JavaScript execution within the generated artifact's browser context. The malicious dependency could manipulate the interface and artwork, inspect data available to the page, capture user input entered into the artifact, initiate unauthorized network requests, or misrepresent downloaded outpu ...[truncated 228 chars]
- A user creates or receives an HTML artifact derived from
- Remediation
View remediation
Remediation Suggestions
- Prefer bundling a reviewed copy of p5.js directly into the generated HTML so the artifact is genuinely self-contained and does not retrieve executable code at runtime.
- If CDN delivery must remain, calculate and specify the official cryptographic Subresource Integrity hash:
html <script src="https://cdnjs.cloudflare.com/ajax/libs/p5.js/1.7.0/p5.min.js" integrity="sha384-REPLACE_WITH_VERIFIED_HASH" crossorigin="anonymous"></script> - Obtain the hash from a trusted source or calculate it from a separately verified release artifact; do not copy an unverified hash from the same delivery channel.
- Retain exact-version pinning and review dependency updates before changing the pinned version or integrity hash.
- Apply a restrictive Content Security Policy that limits script execution and network destinations to explicitly approved sources.
- Consider self-hosting reviewed font resources as well to reduce third-party requests and avoid disclosing routine client metadata to external font providers.
