T09 · Insecure Skill Coding Practices
- Location
references/inject_pack.js:21- Finding
Content-pack injection permits arbitrary script execution in generated workbenches
- Content
View full analysis
` element. JSON validity does not make text safe for an HTML script context. A JSON string may legally contain the literal sequence ``. HTML parsing terminates a script element when this sequence is encountered, even when it appears inside a JavaScript string literal. An attacker-controlled pack can therefore close the engine's script element, introduce a new script or other active HTML, and place the remainder inside a harmless element. For example, a valid JSON string value can contain a payload structurally equivalent to: ```json { "meta": { "grade": "- Remediation
View remediation
/g, '\\u003e') .replace(/&/g, '\\u0026') .replace(/\u2028/g, '\\u2028') .replace(/\u2029/g, '\\u2029'); const injected = `const CONTENT_PACK = ${safeJson};\n` + `const SUBJECTS = CONTENT_PACK.subjects;`; ``` Escaping `<` prevents `` from being recognized by the HTML parser. 3. Prefer storing the pack in a non-executable element: ```html ``` The content must still escape `<` before insertion. Parse it using `JSON.parse(document.getElementById('content-pack').textContent)`. 4. Enforce a strict schema before generating output. Reject unknown fields, malformed arrays, invalid dates, unsafe identifiers, and values exceeding reasonable size limits. 5. Add regression tests containing: - `` - HTML tags in every text field - Unicode line separators - Quotes and backslashes 6. Add a restrictive Content Security Policy. Eliminate inline event handlers and, where feasible, move JavaScript into a separate static file so `script-src 'self'` can be used without `'unsafe-inline'`. ]]>
