T09 · Insecure Skill Coding Practices
- Location
scripts/generate_html.py:246- Finding
Stored HTML and JavaScript Injection Through RSS Content
- Content
View full analysis
` ${tag} × `).join(''); renderArticles(); } ``` ```javascript if (matches.length > 0) { tagSuggestions.innerHTML = matches.map(tag => `${tag}`).join(''); tagSuggestions.style.display = 'block'; } ``` ```javascript container.innerHTML = filtered.map(a => ` `).join(''); ``` Remote values enter the database through `scripts/fetch.py:364-378`: ```python write_queue.put({ 'id': article_id, 'source_id': source_id, 'category': category, 'title': item['title'], 'url': item['url'], 'author': item['author'], 'published_at': item['published_at'], 'tags': tags }) ``` ### Technical Analysis Article titles, URLs, source identifiers, categories, and tags eventually originate from RSS feeds or editable source ...[truncated 2230 chars]- Remediation
View remediation
`, `&`, U+2028, and U+2029 before embedding it. 6. Alternatively, store the article data in a separate JSON file and parse it at runtime. 7. Apply context-specific escaping to any server-generated option text and attribute value. 8. Add a restrictive Content Security Policy that disallows inline scripts and inline event handlers. 9. Add regression tests using values containing ``, quotes, HTML elements, event attributes, and malicious URL schemes. ]]>
