T09 · Insecure Skill Coding Practices
- Location
scripts/landing_builder.py:1440- Finding
Persistent HTML and JavaScript Injection Through Unescaped URL Attributes
- Content
View full analysis
str: name = config.get("name", "Your Brand") desc = config.get("description", "") tagline = config.get("tagline", "") hero_img = config.get("hero_img") or theme_conf.get("hero_img", "") # ... img_html = f'' if hero_img else "" ``` Additional affected HTML attributes are generated as follows: ```python og_image = config.get("hero_img") or theme_conf.get("hero_img", "") url = config.get("url", "https://example.com") ``` ```html ``` ### Technical Analysis The `hero_img` and `url` values can originate from an externally supplied JSON configuration. These values are interpolated directly into double-quoted HTML attributes without HTML attribute escaping or URL validation. Other textual fields use `html_escape()`, but these URL fields bypass that protection. An attacker can include a double quote in `hero_img` to terminate the `src` attribute and append an event handler. For example, a configuration value conceptually equivalent to: ```json { "hero_img": "invalid\" onerror=\"alert(document.domain)" } ``` produces an image element with an attacker-controlled `onerror` handler. Because the generated payload is stored in the output file, the injection executes when that file is subsequently opened or deployed. The Open Graph and Twitter metadata sinks also permit arbitrary attribute or element injection. The directly rendered hero image is the clearest script-execution sink because image error handlers are executable browser events. ...[truncated 1122 chars]
- Remediation
View remediation
' if hero_img else "" ) ``` 2. Escape metadata values in the same way: ```python safe_og_image = html_escape(str(og_image), quote=True) safe_url = html_escape(str(url), quote=True) ``` 3. Parse URLs with `urllib.parse.urlparse()` and allow only explicitly supported schemes, preferably `https`. Reject control characters, quotes, and unsupported schemes such as `javascript:`. 4. Consider using a template engine with automatic contextual escaping if third-party dependencies become acceptable. 5. Add regression tests containing double quotes, single quotes, angle brackets, event handlers, and malicious URL schemes in every configuration field rendered into an HTML attribute. 6. Treat configuration files from untrusted sources as unsafe until all output contexts have validation and escaping. ]]>
