T08 · Insecure Dependencies
- Location
SKILL.md:40- Finding
Mutable Remote JavaScript Dependency in Generated HTML
- Content
View full analysis
import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs'; mermaid.initialize({ startOnLoad: true, theme: 'default' }); ``` ### Technical Analysis The HTML template imports and executes Mermaid directly from jsDelivr. The dependency selector `mermaid@11` pins only the major version, so the actual JavaScript returned can change as new version 11 releases are published. The template does not vendor the dependency locally or otherwise verify an immutable artifact. Consequently, the behavior of an already-generated HTML document depends on mutable third-party infrastructure at the time it is opened. If the Mermaid package, package publishing account, npm distribution path, or CDN infrastructure is compromised, malicious JavaScript could be delivered and executed by the browser. This is classified as `T08: Insecure Dependencies` because the risk originates from an externally hosted, mutable third-party dependency and its supply chain. ### Attack Path 1. A user follows the skill instructions and generates an HTML diagram using the provided template. 2. The user opens that HTML document in a browser while network access is available. 3. The browser requests the module identified by `https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjs`. 4. An attacker who has compromised the relevant package release process, package account, or CDN delivery path causes a malicious version-compatible artifact to be served. 5. The browser executes the returned module in the generated page's origin context without local verification of its contents. This attack path requires compromise or malicious control of an upstream supply-chain component; the audited project itself does not contain a ...[truncated 895 chars]- Remediation
View remediation
