T09 · Insecure Skill Coding Practices
- Location
scripts/markdown_to_html.py:184- Finding
Unsanitized Raw HTML Allows Script Execution in Generated Documents
- Content
View full analysis
Vulnerability Details
File Location:
scripts/markdown_to_html.py:184-185; rendering sinks inassets/templates/docs-slate.html:31,assets/templates/magazine-amber.html:31,assets/templates/product-midnight.html:33, andassets/templates/serif-paper.html:30
Vulnerability Type: Stored cross-site scripting through untrusted Markdown conversion
Risk Level: MediumVulnerable Code
scripts/markdown_to_html.py:184-185:python "--from", "markdown+yaml_metadata_block+emoji+footnotes+pipe_tables+grid_tables+task_lists+fenced_divs+fenced_code_attributes+raw_attribute+tex_math_dollars",Each bundled template inserts the generated HTML body without a sanitization layer:
html $body$Technical Analysis
The converter invokes Pandoc's Markdown reader without disabling raw HTML. The enabled
raw_attributeextension also permits attributes associated with raw output constructs. Attacker-controlled Markdown can therefore contain active HTML, including script elements, event-handler attributes, dangerous links, or embedded frames.Pandoc converts the supplied document and the bundled templates insert the resulting content directly through
$body$. No allowlist-based HTML sanitizer, Content Security Policy, or trusted-input restriction is applied before the final HTML file is written.A malicious Markdown input could contain content such as:
markdown # Shared Document <script> // Attacker-controlled browser-side behavior alert(document.domain); </script>When the generated document is opened, the browser may execute the embedded script. Exploitability and accessible data depend on how the output is opened or hosted. Hosting the document under a trusted application's origin creates substantially greater risk than opening it as an isolated local file.
Attack Path
- An attacker creates or modifies a Markdown document containing active HTML or event-handler attr ...[truncated 1311 chars]
- Remediation
View remediation
Remediation Suggestions
-
Disable raw HTML in the Pandoc reader configuration by removing the relevant capability explicitly:
python "--from", "markdown-raw_html+yaml_metadata_block+emoji+footnotes+pipe_tables+grid_tables+task_lists+fenced_divs+fenced_code_attributes-raw_attribute+tex_math_dollars", -
Apply a mature allowlist-based HTML sanitizer after conversion and before writing or publishing the final document. Allow only required tags and attributes, and reject:
script,iframe,object, andembedelements.- Attributes beginning with
on, such asonclickandonerror. - Dangerous URI schemes such as
javascript:. - Unnecessary inline styles and active embedded content.
-
If raw HTML is a required feature, disable it by default and expose it only through an explicitly named option such as
--allow-unsafe-html. Document that this option must only be used with trusted input. -
Add a restrictive Content Security Policy to bundled templates as defense in depth. For example, disallow inline scripts and restrict resource origins. CSP should supplement sanitization rather than replace it.
-
When generated documents are hosted, serve untrusted output from an isolated origin without access to application cookies or sensitive browser storage.
-
Add regression tests using raw script tags, event-handler attributes,
javascript:links, SVG-based payloads, and embedded frames. Verify that active content is removed or rendered inert.
-
