T09 · Insecure Skill Coding Practices
- Location
scripts/viz_wizard.py:996- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
{chart_title}
""") html = html.replace('__CHART_SLOTS__', '\n'.join(slots)) ``` The chart configuration is inserted into an executable inline script: ```python html = html.replace('__CHARTS_JSON__', json.dumps(charts_config, default=str)) ``` A CSV-derived label is subsequently interpreted as HTML by the generated dashboard: ```javascript card.innerHTML = `${label} — Sum${fmt(total)}`; ``` ### Technical Analysis User-controlled CLI titles, CSV headers, and C ...[truncated 2264 chars]- Remediation
View remediation
', '\\u003e') .replace('\u2028', '\\u2028') .replace('\u2029', '\\u2029') ) ``` 3. Prefer placing serialized data in a non-executable ``, ``, quotation marks, ampersands, and Unicode line separators. ]]>
