T09 · Insecure Skill Coding Practices
- Location
scripts/newsletter_assemble.py:64- Finding
Unescaped Newsletter Content Permits HTML and Attribute Injection
- Content
View full analysis
' f'{block.get("image_credit","")}
' ) paras = "".join(f"{p}
" for p in block.get("paras", [])) return f""" {img_html}{block.get('title','Untitled')}
{block.get('byline','')} · {block.get('date','')}
{paras} """ def render_listing(block): """Render a single listing block to HTML.""" img_html = "" if block.get("image_url"): img_html = ( f'' ) venue = block.get("venue", "") dt = block.get("datetime", "") why = block.get("why", "") meta_parts = [] if venue: meta_parts.append(venue) if dt: meta_parts.append(dt) meta = " · ".join(meta_parts) return f"""
{img_html}""" ``` Additional unsafe interpolation occurs in source and template rendering: ```python srcs = ", ".join(f'{u[:60]}' for u in parts.get("sources", [])) or "None" replacements = { "{{PUBLICATION_NAME}}": ctx.get("publication_name", "Newsletter"), "{{TAGLINE}}": ctx.get("tagline", ""), "{{DATE} ...[truncated 2869 chars]{block.get("name","")}
{f'{meta}
' if meta else ''}{why}
{f'' if block.get("url") else ""}- Remediation
View remediation
