T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:231- Finding
XML Injection Through Unescaped Author Metadata
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 231–233
Vulnerability Type: XML injection caused by missing output encoding
Risk Level: MediumVulnerable Code
python lines.append(f' <name>{author.name}</name>') if author.affiliation: lines.append(f' <aff>{author.affiliation}</aff>')Technical Analysis
The XML generator interpolates the user-controlled
author.nameandauthor.affiliationvalues directly into XML markup. It does not escape XML metacharacters such as&,<,>,", or'.These values may originate from an input JSON file supplied with
--input, from the--authorscommand-line option, or from interactive input. A malicious value can therefore terminate the intended element and inject additional XML elements or attributes into the generated document.For example, a crafted author name conceptually equivalent to:
text Alice</name><injected>attacker-controlled content</injected><name>would alter the structure of the generated XML rather than being represented as literal author text. Even ordinary names or affiliations containing
&or<can produce malformed XML.Attack Path
- An attacker prepares an input JSON document containing XML markup in an author's
nameoraffiliation. - A user or automated workflow invokes the tool with that file and requests XML output, for example:
bash python scripts/main.py --input attacker-controlled.json --format xml --output contribution.xml generate_xml()inserts the malicious value directly into the document.- The resulting file contains attacker-controlled XML structure or becomes malformed.
- A downstream journal submission, metadata, or document-processing system consumes the compromised XML.
Impact Assessment
The vulnerability allows modification of the generated docume ...[truncated 512 chars]
- An attacker prepares an input JSON document containing XML markup in an author's
- Remediation
View remediation
Remediation Suggestions
Construct the output with a standard XML API such as
xml.etree.ElementTreerather than assembling markup through string interpolation. XML libraries automatically encode text nodes correctly when serializing the document.Example hardening approach:
python import xml.etree.ElementTree as ET root = ET.Element("contrib-group") for author in self.contribution.authors: contrib = ET.SubElement(root, "contrib", {"contrib-type": "author"}) ET.SubElement(contrib, "name").text = author.name if author.affiliation: ET.SubElement(contrib, "aff").text = author.affiliation output = ET.tostring(root, encoding="unicode", xml_declaration=False)If manual generation is unavoidable, apply
xml.sax.saxutils.escape()to every user-controlled text value before interpolation. Also validate input types and reasonable length limits, and add regression tests covering ampersands, angle brackets, quotes, closing tags, and nested-element payloads.
