T08 · Insecure Dependencies
- Location
assets/slide-template.html:8- Finding
Mutable CDN Dependencies Are Loaded Without Subresource Integrity
- Content
View full analysis
``` ```html ``` ### Technical Analysis The presentation template loads executable JavaScript and stylesheets directly from jsDelivr. Dependency URLs use mutable major-version selectors such as `@3`, `@4`, and `@10`, rather than exact immutable versions. The resource elements also lack Subresource Integrity (`integrity`) metadata. Consequently, the code executed when a generated presentation is opened is not necessarily identical to the dependency code available when the Skill was audited. A compromised CDN response, upstream package compromise, or malicious release within an accepted major-version range could cause attacker-controlled JavaScript to execute in the presentation's browser context. This is a supply-chain weakness rather than evidence that the current CDN resources are malicious. ### Attack Path 1. A user generates or distributes an HTML presentation based on the supplied template. 2. A viewer opens the presentation while network access is available. 3. The browser retrieves Revea ...[truncated 1192 chars]- Remediation
View remediation
``` 3. Prefer vendoring reviewed dependency files locally when presentations must remain reproducible or operate in sensitive environments. 4. Establish an explicit dependency-update process that includes version review, integrity-hash regeneration, and security testing. 5. Add a restrictive Content Security Policy that permits scripts and styles only from required sources and blocks unnecessary connections. 6. Consider generating fully self-contained presentations so opening a deck does not retrieve executable content from the network. ]]>
