T09 · Insecure Skill Coding Practices
- Location
scripts/particle-text.js:105- Finding
Stored JavaScript Injection in Generated Particle Animation HTML
- Content
View full analysis
\n'; html += '\n\n'; // ... html += '` can terminate the enclosing script element before JavaScript parsing occurs. The attacker can then append a new script element or arbitrary HTML. The defined `escapeHtml()` function is not applied to the serialized particle data. Even if it were applied naively, HTML escaping would need to be designed specifically for data embedded inside an executable script. ### Attack Path 1. An attacker provides crafted text containing an HTML script termination sequence, such as a value based on: ```text ``` 2. The victim or an automated agent runs: ```bash node scripts/particle-text.js --text "" ``` 3. The script creates `particle-text-demo.html` in the project directory. 4. The victim opens the generated file as directed by the documentation. 5. The browser's HTML parser terminates the original script at the injected `` sequ ...[truncated 779 chars]- Remediation
View remediation
/g, '\\u003e') .replace(/&/g, '\\u0026') .replace(/\u2028/g, '\\u2028') .replace(/\u2029/g, '\\u2029'); } const particlesJson = serializeForInlineScript(particles); ``` 3. Prefer placing serialized data in a non-executable JSON element and reading it safely: ```html ``` The JSON content must still encode `<` as `\u003c` to prevent HTML parser termination. 4. Better still, generate the document using a trusted templating system with context-aware escaping. 5. Add tests containing ``, `
