T09 · Insecure Skill Coding Practices
- Location
scripts/sweep.sh:62- Finding
Unescaped Library Data Allows HTML Injection in Generated Email
- Content
View full analysis
Vulnerability Details
File Location:
scripts/sweep.sh, lines 62-76 and 104-111
Vulnerability Type: HTML injection caused by missing output encoding
Risk Level: MediumVulnerable Code
bash ROW_IDX=0 while IFS= read -r line; do NAME=$(echo "$line" | jq -r '.name') LAST=$(echo "$line" | jq -r '.last_played // "Never"') PATH_=$(echo "$line" | jq -r '.install_path // "N/A"') BG=$([[ $((ROW_IDX % 2)) -eq 0 ]] && echo "" || echo "background:#fafafa") EMAIL_BODY+="<tr style='$BG'><td style='padding:6px'>$NAME</td><td style='padding:6px'>$LAST</td><td style='padding:6px'>$PATH_</td></tr>" echo " • $NAME — last played ${LAST}" ROW_IDX=$((ROW_IDX + 1)) done < <(echo "$STALE" | jq -c '.[]') EMAIL_BODY+="</table>" EMAIL_BODY+="<p style='color:#888;margin-top:16px'>Generated by gog-stale-games-cleanup on $TODAY</p>"The resulting value is sent explicitly as HTML:
bash cat <<HEREDOC | himalaya --account "$EMAIL_ACCOUNT" template send From: $(jq -r ".accounts.${EMAIL_ACCOUNT}.email" /root/.openclaw/workspace/config/himalaya.toml 2>/dev/null || echo "$RECIPIENT") To: $RECIPIENT Subject: $SUBJECT Content-Type: text/html $EMAIL_BODY HEREDOCTechnical Analysis
The script reads
name,last_played, andinstall_pathfrom the supplied GOG library JSON and concatenates them directly into an HTML document. It does not encode HTML-sensitive characters such as&,<,>,", or'.Although the repository includes a JSON Schema, the script does not validate its input against that schema. Type validation alone would not address this issue because malicious HTML is still a valid JSON string. A crafted game name or installation path can therefore introduce arbitrary markup into the outgoing email.
For example, an attacker-controlled
install_pathcould contain an external image element. When a mail client renders the message and permits remote images, it could contact an attacker-controlled server. Injected markup co ...[truncated 1540 chars]- Remediation
View remediation
Remediation Suggestions
- HTML-encode every value originating from the library JSON before adding it to
EMAIL_BODY. At minimum, encode&,<,>,", and'. - Prefer a maintained template or serialization mechanism that applies contextual HTML escaping automatically rather than assembling markup through string concatenation.
- Validate the input JSON against
references/gog_library_schema.jsonbefore processing it. Treat validation as defense in depth rather than a replacement for output encoding. - Consider sending a plain-text report if HTML formatting is not essential.
- Add regression tests containing values such as:
<img src="https://attacker.invalid/track"><a href="https://attacker.invalid">Review game</a>Game & Expansion <Edition>
- Verify that test output contains encoded text, such as
<img, rather than executable markup.
A shell-compatible escaping helper could process each dynamic field before interpolation, but a structured HTML template library with automatic escaping is preferable.
- HTML-encode every value originating from the library JSON before adding it to
