T09 · Insecure Skill Coding Practices
- Location
scripts/api_client.py:843- Finding
Stored script injection in receipt preview
- Content
View full analysis
${f.label}${val}`; document.getElementById('receiptDataPanel').innerHTML = html; ``` ### Technical Analysis The receipt preview embeds API-controlled OCR results directly inside a `` terminates the surrounding script element regardless of whether that sequence occurs inside a JavaScript string. An attacker-controlled receipt field could therefore contain a value such as: ```html ``` When the generated preview is opened, the browser interprets the injected element as executable script. There are also secondary DOM injection sinks because OCR values are interpolated into HTML strings and assigned to `innerHTML` without applying the available `escapeHtml()` function. The sour ...[truncated 1760 chars]- Remediation
View remediation
` element. Escape at least `<`, `>`, `&`, U+2028, and U+2029 before embedding: ```python def safe_script_json(value): return ( json.dumps(value, ensure_ascii=False) .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 2. Prefer storing serialized data in a non-executable ``, ``, quotes, backticks, and malformed URLs. ]]>
