T09 · Insecure Skill Coding Practices
- Location
scripts/epub_generator.py:134- Finding
Unescaped document-derived chapter titles allow XHTML injection into generated EPUB files
- Content
View full analysis
epub.EpubHtml: """ 创建单个章节 Args: chapter: 章节信息 css_item: CSS样式项 Returns: EPUB HTML章节对象 """ # 创建HTML内容 html_content = f""" {chapter.title}{chapter.title}
{self._format_content(chapter.content)}""" # 创建章节 epub_chapter = epub.EpubHtml( title=chapter.title, file_name=f'{chapter.id}.xhtml', content=html_content ) ``` ### Technical Analysis The chapter title is interpolated directly into both the XHTML `` element and the visible `<h1>` element without XML or HTML escaping. Chapter titles are derived from OCR output by `TextCleaner.detect_chapter_titles()` and can consequently be controlled through the contents of an input PDF. When no chapter title is detected, document metadata can also supply the title. The implementation correctly escapes `&`, `<`, and `>` for chapter body content in `_format_content()`, but no equivalent protection is applied to `chapter.title`. An input such as a chapter heading containing closing tags and additional XHTML can therefore alter the structure of the generated chapter document. EPUB readers differ significantly in their treatment of active content and remote resources. A permissive or vulnerable reader could process injected links, images, forms, styles, or scripts. Even w ...[truncated 1565 chars]- Remediation
View remediation
` and `` elements. 2. Prefer constructing XHTML through an XML library such as `lxml.etree` rather than assembling it with formatted strings. XML libraries perform context-appropriate escaping automatically when text nodes are assigned correctly. 3. Treat metadata values passed to EbookLib as untrusted as well. Normalize them to strings, reject forbidden XML control characters, and enforce reasonable length limits. 4. Validate every generated XHTML document with a strict XML parser before packaging the EPUB. 5. Run an EPUB validation tool against the final artifact and fail closed if malformed markup or prohibited active content is detected. 6. Add regression tests using chapter titles containing: - `<`, `>`, `&`, single quotes, and double quotes. - Closing tags followed by injected elements. - Remote image and link elements. - Invalid XML control characters. ]]>
