T09 · Insecure Skill Coding Practices
- Location
charts/map-compare.html:277- Finding
Persistent Cross-Site Scripting Through Unsanitized Chart Template Values
- Content
View full analysis
{ const item = document.createElement('div'); item.className = 'direction-item'; item.innerHTML = `${d.name}:${d.reason} · 第一步:${d.step}`; list.appendChild(item); }); ``` Related direct JavaScript-context substitution: ```javascript const pathName = "{{path_name}}"; const xLabels = ["现在", "1个月", "3个月", "6个月", "12个月"]; const dataPathA = {{data_path_a}}; const dataStatusQuo = {{data_status_quo}}; const milestoneIndex = {{milestone_index}}; const milestoneLabel = "{{milestone_label}}"; const turningPointIndex = {{turning_point_index}}; const hoverLabelsPathA = {{hover_labels_path_a}}; const hoverLabelsStatusQuo = {{hover_labels_status_quo}}; ``` ### Technical Analysis The chart system substitutes values derived from user conversations, uploaded CVs, and persistent memory directly into executable JavaScript. String values are placed between JavaScript quotes without conte ...[truncated 2348 chars]- Remediation
View remediation
`, then parse it after safely encoding characters that can terminate the element. 6. Apply a restrictive Content Security Policy that disallows inline scripts and event handlers. 7. Render generated charts in a sandboxed, unique-origin iframe. Do not grant `allow-same-origin`, top-navigation, form submission, pop-up, or parent-DOM permissions unless strictly required. 8. Add automated tests using payloads containing quotes, ``, template-literal syntax, HTML event handlers, and malformed arrays. ]]>
