T09 · Insecure Skill Coding Practices
- Location
scripts/generate_html.py:225- Finding
Stored Cross-Site Scripting in Generated HTML Reports
- Content
View full analysis
{ if (dateSelect && item.date !== dateSelect) return false; if (search && !item.title.toLowerCase().includes(search)) return false; return true; }); document.getElementById('showCount').textContent = filtered.length; const container = document.getElementById('hotList'); if (filtered.length === 0) { container.innerHTML = ``; return; } const grouped = {}; filtered.forEach(item => { if (!grouped[item.date]) grouped[item.date] = []; grouped[item.date].push(item); }); let html = ''; Object.keys(grouped).sort().reverse().forEach(date => { html += grouped[date].map(item => `📰没有找到记录${item.rank}${item.title}${item.label ? `${item.label}` : ''} ${item.popularity ? `🔥 ${formatHeat(item.popularity)}` : ''}- Remediation
View remediation
` block. Store it in a non-executable JSON element or external JSON file. If inline embedding is required, escape HTML-significant characters, including replacing `<` with `\u003c`. 4. Add `rel="noopener noreferrer"` to links opened with `target="_blank"`. 5. Add a restrictive Content Security Policy that disallows inline scripts and limits connections and navigation to required destinations. 6. Treat all API and database values as untrusted, even when the current provider is expected to be legitimate. 7. Regenerate the checked-in `data/index.html` after correcting the generator because the existing artifact contains the same unsafe rendering logic. ]]>
