T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:34- Finding
Unescaped Prospect Data Allows HTML Injection in Generated Reports
- Content
View full analysis
{p['name']}{p['position']}Location: {p.get('location', 'N/A')} | LinkedIn ProfileGap Analysis:
-
"""
for need in p.get('needs', []):
html += f"
- {need} " html += f"""
Pitch Idea: {p.get('pitch', 'N/A')}``` ### Technical Analysis The report generator directly interpolates JSON-derived values into HTML without applying context-appropriate escaping. The affected values include `name`, `position`, `location`, each entry in `needs`, and `pitch`. An attacker-controlled value containing HTML can therefore terminate the intended element and inject arbitrary markup, including script elements, event handlers, embedded resources, or misleading report content. The `linkedin_url` field is inserted directly into an `href` attribute without quotation escaping or URL-scheme validation. A crafted value can break out of the attribute or introduce a dangerous scheme such as `javascript:`. Although the precise effect depends on the browser or HTML-to-PDF renderer, active-content renderers may execute scripts or initiate external network requests. The data is expected to originate from researched LinkedIn profiles and company websites. Consequently, prospect-controlled content crosses an external trust boundary before reaching this unsa ...[truncated 1736 chars]- Remediation
View remediation
