T09 · Insecure Skill Coding Practices
- Location
scripts/add_native_slide_numbers.py:104- Finding
Unescaped Input Interpolation in Generated OOXML
- Content
View full analysis
' f'' f'' f'' f'{slide_number}' ) paragraph._p.append(parse_xml(field_xml)) ``` A second XML fragment interpolates `placeholder_idx` without escaping: ```python nv_pr.append(parse_xml( f'' )) ``` The value is obtained from an input presentation: ```python def slide_number_placeholder_idx(slide) -> str: layout_fields = slide.slide_layout._element.xpath( './/p:ph[@type="sldNum"]' ) master_fields = slide.slide_layout.slide_master._element.xpath( './/p:ph[@type="sldNum"]' ) if len(layout_fields) != 1 or len(master_fields) != 1: raise RuntimeError( "PowerPoint-compatible native numbering requires exactly one " "sldNum placeholder in both the slide layout and slide master" ) return layout_fields[0].get("idx", "0") ``` ### Technical Analysis The script constructs OOXML fragments with Python formatted strings and then passes the resulting strings to `parse_xml()`. Two interpolated values are not escaped or constrained: 1. `font_name` is supplied directly through the command-line `--font` argument. 2. `placeholder_idx` originates from the `idx` attribute of a slide-number placeholder in the input PPTX. An XML attribute can contain encoded quote or markup characters that are decoded when ...[truncated 2291 chars]- Remediation
View remediation
str: if not re.fullmatch(r"[0-9]+", value): raise ValueError("slide-number placeholder idx must contain digits only") return value ``` Apply this validation before creating the new placeholder. 3. **Constrain command-line font names.** Enforce a reasonable maximum length and reject control characters and XML-significant characters. Prefer an allowlist of supported fonts when feasible. 4. **Use element construction for the field.** Create `a:fld`, `a:rPr`, `a:latin`, `a:solidFill`, `a:srgbClr`, and `a:t` as separate elements. Set `typeface`, `val`, `id`, and `type` using element attribute APIs rather than string interpolation. 5. **Fail safely on untrusted presentations.** Catch XML and package-processing errors, avoid writing a partial output file, and return a clear validation error. 6. **Add security regression tests.** Test font names and placeholder indices containing quotes, angle brackets, ampersands, encoded entities, excessive lengths, and malformed Unicode. Verify that such input is either safely encoded or rejected and cannot alter the intended OOXML tree. ]]>
