T09 · Insecure Skill Coding Practices
- Location
lib/convert-pages.js:45- Finding
Untrusted HTML Executes with Unrestricted Network Access in an Unsandboxed Browser
- Content
View full analysis
Vulnerability Details
File Location:
lib/convert-pages.js, lines 45-61
Vulnerability Type: Uncontained execution of active HTML content
Risk Level: HighVulnerable code:
javascript // 启动浏览器 browser = await puppeteer.launch({ headless: true, args: ['--no-sandbox', '--disable-setuid-sandbox'] }); const page = await browser.newPage(); // 设置视口大小 await page.setViewport({ width: pageWidth, height: pageHeight, deviceScaleFactor: 2 // 2x 分辨率,获得更清晰的图片 }); // 加载 HTML 内容 await page.setContent(htmlContent, { waitUntil: 'networkidle0' });Technical Analysis
The Skill accepts a caller-controlled HTML file and passes its contents to
page.setContent(). By default, Chromium executes JavaScript contained in that document and permits it to initiate network requests. No request interception, destination allowlist, private-address filtering, or JavaScript restriction is applied.At the same time, Chromium is launched with both
--no-sandboxand--disable-setuid-sandbox. These flags remove an important browser-process isolation boundary. Rendering HTML requires a browser engine, but unrestricted active-content execution and removal of the browser sandbox exceed the minimum privileges needed to produce screenshots.A hostile document can therefore:
- Execute arbitrary browser-side JavaScript.
- Transmit document data to an attacker-controlled endpoint.
- Load attacker-controlled remote scripts and other resources.
- Send requests to loopback, private-network, link-local, or cloud metadata addresses.
- Perform blind cross-site request forgery against services reachable from the rendering host.
- Attempt exploitation of browser vulnerabilities with reduced operating-system containment.
Browser same-origin controls may prevent JavaScript from reading some cross-origin responses, but they do not prevent all outbound or state-changing requests. A browser vulne ...[truncated 1428 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--no-sandboxand--disable-setuid-sandbox, and configure the deployment environment so Chromium can run with its normal sandbox enabled. - If JavaScript is not necessary for rendering, call
page.setJavaScriptEnabled(false)before loading the document. - Enable request interception and deny network requests by default. Allow only resource schemes and explicitly trusted domains required for rendering.
- Explicitly block loopback, private, link-local, multicast, and cloud metadata address ranges after DNS resolution. Revalidate redirects to prevent allowlist bypass.
- Consider rewriting remote resources into reviewed local assets so screenshot generation can run without network access.
- Enforce navigation, rendering, and request timeouts to limit denial-of-service conditions.
- Run the renderer as a dedicated unprivileged user in an isolated container or virtual machine with a read-only filesystem, restricted egress, bounded CPU and memory, and access only to the selected input and output locations.
- Document whether input HTML is trusted. If untrusted files are supported, add security-focused validation and containment tests.
- Remove
