T03 · Remote Payload Retrieval and Execution
- Location
templates/en/dark-tech.html:7- Finding
Generated reports execute mutable third-party JavaScript without integrity verification
- Content
View full analysis
``` ```javascript /* Preload html2canvas eagerly — fires while user reads, so first export is instant */ let libPromise = null; function loadLib() { if (libPromise) return libPromise; libPromise = new Promise(resolve => { if (window.html2canvas) { resolve(); return; } const s = document.createElement('script'); s.src = 'https://cdn.jsdelivr.net/npm/html2canvas@1/dist/html2canvas.min.js'; s.onload = resolve; document.head.appendChild(s); }); return libPromise; } loadLib(); /* start loading immediately */ ``` ### Technical Analysis The template loads and executes JavaScript directly from public CDNs. The Chart.js and html2canvas URLs select mutable major-version ranges (`@4` and `@1`) rather than exact, audited releases. None of the external scripts use Subresource Integrity. Consequently, the effective executable code can change after the Skill package has been reviewed. The html2canvas dependency is injected eagerly as soon as the report is opened, even if the user never requests image export. This network and code-execution behavior is not the minimum privilege necessary for viewing a generated report. Third-party JavaScript executes with the same browser-page privileges as the report’s own scripts. It can read the report DOM, including confidential report text, KPIs, tables, and user edits; observe browser interactions; modify rendered content or exported images; and initiat ...[truncated 1704 chars]- Remediation
View remediation
