T09 · Insecure Skill Coding Practices
- Location
scripts/generate_radar.py:184- Finding
Untrusted report metadata permits stored script injection in generated HTML
- Content
View full analysis
{project_name} ``` ```python for dim, score in zip(dimensions, scores): score_class = "score-high" if score >= 7 else ("score-low" if score < 5 else "") html_content += f'{dim}{score:.0f}/10\n' ``` Dimension data is also embedded in an executable script block: ```python indicator: ''' + json.dumps(indicator_config, ensure_ascii=False) + ''', ``` ### Technical Analysis The HTML report generator treats values read from the input JSON file as trusted markup. In particular, `project_name` and each entry in `dimensions` are interpolated into HTML without contextual output encoding. An attacker-controlled dimension such as the following is interpreted as markup when the report is opened: ```html``` The use of `json.dumps()` for the ECharts configuration does not provide safe HTML-script embedding. JSON serialization can preserve a sequence such as ``, allowing an attacker to terminate the existing script element and inject a new HTML or script element. Input validation only verifies that `dimensions` and `scores` exist and each contains nine entries. It does not validate dimension names, score types, score ranges, metadata length, or prohibited markup. ### Attack Path 1. An attac ...[truncated 1377 chars]
- Remediation
View remediation
", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 3. Prefer a template engine with automatic HTML escaping, such as Jinja2 with auto-escaping explicitly enabled. 4. Validate input against a strict schema: - Require exactly the expected nine dimension names, or map internal identifiers to fixed display labels. - Require scores to be finite numeric values between 0 and 10. - Restrict metadata to reasonable lengths. - Reject unexpected object and array types. 5. Add a restrictive Content Security Policy that disallows inline scripts and limits script sources. CSP should be defense in depth rather than a replacement for encoding. 6. Add regression tests using payloads containing ``, event-handler attributes, quotes, ampersands, and Unicode line separators. ]]>
