T09 · Insecure Skill Coding Practices
- Location
scripts/run-recording.mjs:175- Finding
Arbitrary JavaScript Execution in the Active Browser Page
- Content
View full analysis
{ const fn = new Function(`return (${code});`)(); return fn(args || {}); }, { code: step.code, args: step.args || {} } ); if (step.holdMs) await page.waitForTimeout(step.holdMs); return { browser, page, interactionLog }; } ``` ### Technical Analysis The runner reads a JSON plan and accepts an `evaluate` step whose `code` property is compiled using `new Function`. No schema enforcement, operation allowlist, origin restriction, integrity check, or trust validation is applied before the code executes through Puppeteer in the active page. The dynamically supplied function runs in the context of the currently loaded web page. It can access DOM content and browser-accessible application state, perform arbitrary page interactions, and initiate network requests permitted by the page's execution environment. If the connected browser contains authenticated sessions, the code may operate with those existing session privileges. The code is also copied into the interaction log, but logging does not mitigate its execution. ### Attack Path 1. An attacker supplies or modifies a recording plan. 2. The plan includes an `evaluate` step with malicious JavaScript in `step.code`. 3. The runner parses the plan without validating the code. 4. `new Function` compiles the supplied expression. 5. `page.evaluate` executes it in the active browser page. 6. The payload reads sensitive page data or performs actions using the page's authenticated session. 7. The payload can transmit accessible information through requests initiated from the page, subject to browser security controls. ### Impact Assessment Successful exp ...[truncated 473 chars]- Remediation
View remediation
