T09 · Insecure Skill Coding Practices
- Location
scripts/export_markdown.py:478- Finding
Untrusted Markdown Can Inject Active Content into Generated HTML
- Content
View full analysis
str: return ( "markdown+yaml_metadata_block+emoji+footnotes+pipe_tables+grid_tables+task_lists+" "fenced_divs+fenced_code_attributes+raw_attribute+tex_math_dollars" ) ``` Each bundled HTML template then inserts Pandoc's generated body directly into the document. For example, `assets/html/templates/docs-slate.html` contains: ```html $body$ ``` The equivalent output sink appears in all other bundled HTML templates: ```html $body$ ``` ### Technical Analysis Pandoc's `raw_attribute` extension permits input authors to mark fenced content for direct emission in a target format, including HTML. The generated `$body$` is inserted into the final page without an HTML sanitization stage. The bundled templates also do not establish a restrictive Content Security Policy. An attacker controlling Markdown input can therefore submit raw HTML containing active elements such as scripts, event-handler attributes, malicious forms, or iframes. For example, a fenced raw HTML block can be constructed as follows: ```markdown ```{=html} ``` ``` When exported to HTML, the raw block can be preserved in the generated body and executed when a user opens the document ...[truncated 1743 chars]- Remediation
View remediation
str: return ( "markdown+yaml_metadata_block+emoji+footnotes+pipe_tables+grid_tables+task_lists+" "fenced_divs+fenced_code_attributes+tex_math_dollars-raw_html-raw_attribute" ) ``` 2. If raw HTML is a required feature, expose it only through an explicit option such as `--allow-unsafe-html`. Clearly document that the option must not be used with untrusted Markdown. 3. Sanitize Pandoc's HTML output before inserting or publishing it. Use a maintained allowlist sanitizer and reject at least: - `script`, `iframe`, `object`, `embed`, and active form elements. - Inline event handlers such as `onclick` and `onerror`. - Dangerous URL schemes such as `javascript:`. - Unexpected `data:` URLs and external resource references, according to the deployment policy. 4. Add a restrictive Content Security Policy to bundled templates as defense in depth. A baseline for self-contained documents could prohibit scripts and embedded objects: ```html ``` The exact policy should be adjusted if externally linked assets are intentionally supported. 5. Add regression tests that export hostile Markdown and verify that generated HTML does not contain executable scripts, event-handler attributes, dangerous URL schemes, frames, or forms unless an explicitly unsafe mode is selected. 6. Treat Markdown, custom templates, metadata files, and CSS from external users as untrusted input throughout the conversion and publication pipeline. ]]>
