T09 · Insecure Skill Coding Practices
- Location
scripts/build_explorer.py:420- Finding
Stored HTML and JavaScript Injection in Generated Family Tree Dashboard
- Content
View full analysis
{TITLE} ``` ```html- Remediation
View remediation
', '\\u003e') .replace('\u2028', '\\u2028') .replace('\u2029', '\\u2029') ) ``` Apply this function to people, family, and statistics data. 2. **Prefer non-executable JSON containers.** Store serialized data in ` ``` ```javascript const PEOPLE = JSON.parse( document.getElementById('people-data').textContent ); ``` 3. **Eliminate `innerHTML` for untrusted data.** Construct elements through DOM APIs and assign GEDCOM values using `textContent`: ```javascript const place = document.createElement('div'); place.className = 'person-place'; place.textContent = '📍 ' + p.birthPlace; ``` Apply this change to people cards, timeline entries, alerts, charts, tree nodes, spotlight cards, fun facts, and the person modal. 4. **Escape display metadata by output context.** HTML-escape `TITLE` and `SUBTITLE` before placing them in ``, headings, paragraphs, or attributes. Do not rely on one generic escaping method for HTML text, JavaScript strings, and HTML attributes. 5. **Remove string-based inline event handlers.** Replace generated `onclick` attributes with `addEventListener`. Keep identifiers in JavaScript variables or validated `data-*` attributes rather than interpolating them into executable source. 6. **Add a restrictive Content Security Policy as defense in depth.** Remove inline scripts and hand ...[truncated 920 chars]
