T09 · Insecure Skill Coding Practices
- Location
dashboard.html:327- Finding
DOM-Based Code Injection Through Untrusted Job URLs
- Content
View full analysis
${i+1}${escHtml(job.title)}${escHtml(job.company)} · ${escHtml(job.location || '')}${tagsHtml}`; ``` ### Technical Analysis The dashboard accepts an arbitrary user-selected JSON file and assigns its parsed contents to `jobsData`. While job titles, companies, and locations are processed through `escHtml()`, the `job.url` value is inserted directly into an HTML string containing an inline JavaScript event handler. A single quote in the URL terminates the JavaScript string passed to `window.open()`. The remainder of the value can then inject JavaScript into the `onclick` handler. Because the constructed markup is assigned through `innerHTML`, the browser parses the injected handler as executable code. For example, this URL value ...[truncated 1670 chars]${job.match_score.toFixed(3)}- Remediation
View remediation
{ window.open(safeUrl, '_blank', 'noopener,noreferrer'); }); } ``` ]]>
