T09 · Insecure Skill Coding Practices
- Location
assets/template.html:134- Finding
Unsanitized Resume Data Enables HTML and JavaScript Injection
- Content
View full analysis
{ const sep = i < data.info.length - 1 ? '|' : ''; return `${item}${sep}`; }).join(''); return ``; } ``` ```javascript function renderProjectList(projList) { const items = projList.map(p => { const techHtml = p.tech.map(t => `${t}`).join(''); const linkHtml = p.link ? `${p.link}` : ''; const listHtml = p.items.length > 0 ? `${data.name}
${data.tagline}${infoHtml}- ${p.items.map(i => `
- ${i} `).join('')}
`; }).join(''); return `${nameHtml} ${p.date}${linkHtml}${p.desc} ${listHtml}${techHtml}${renderSectionTitle('项目经验')} ${items}`; } ``` ```javascript function render() { const app = document.getElementById('app'); const d = resumeData; const sections = []; if (d.header) sections.push(renderHeader(d.header)); if (d.summary) sections.push(renderSummary(d.summary)); if (d.workExperience && d.workE ...[truncated 3605 chars]- Remediation
View remediation
... ``` - Before embedding JSON in HTML, escape at least `<` as `\u003c` so that user data cannot form ``. - Read and parse it using: ```javascript const resumeData = JSON.parse( document.getElementById('resume-data').textContent ); ``` - Alternatively, load data from a separately generated JSON file under an appropriately restrictive local policy. 3. **Validate the complete input schema** - Require the expected object, array, and string types. - Enforce reasonable length limits and reject unexpected properties. - Normalize imported resume content to plain text before rendering. - Do not preserve HTML from PDF, DOCX, HTML, Markdown, or text imports. 4. **Validate project links** - Parse links with the `URL` API. - Allow only an explicit set of schemes, preferably `https:` and optionally `http:`. - Reject `javascript:`, `data:`, `file:`, and other unneeded schemes. - Set link text with `textContent` and the validated URL through the DOM `href` property. - When using `target="_blank"`, also set `rel="noopener noreferrer"`. 5. **Apply defense-in-depth browser controls** - Add a restrictive Content Security Policy that blocks inline scripts and event handlers. - Permit network connections only when strictly required; otherwise use `connect-src 'none'`. - Avoid granting the PDF-rendering browser access to privileged automation bridges or unrelated local files ...[truncated 386 chars]
