T09 · Insecure Skill Coding Practices
- Location
dashboard/index.html:1278- Finding
Arbitrary HTML and JavaScript Injection in the Local Dashboard
- Content
View full analysis
{ try { data = JSON.parse(e.target.result); renderDashboard(); } catch (err) { alert('Error parsing JSON file: ' + err.message); console.error(err); } }; reader.onerror = () => alert('Error reading file'); reader.readAsText(file); } ``` Parsed values are interpolated directly into HTML: ```javascript function renderStats() { const grid = document.getElementById('stats-grid'); const snps = data.snps_analyzed || data.total_snps || 0; const format = data.format_detected || data.format || 'Unknown'; const criticalCount = (data.critical_alerts || []).length; const highCount = (data.high_priority || []).length; grid.innerHTML = `${snps.toLocaleString()}SNPs Analyzed${format}File Format${criticalCount}Critical Alerts${highCount}- Remediation
View remediation
... ``` Escape at least `<`, `>`, `&`, U+2028, and U+2029 before embedding, then parse the element’s text content. 5. Add a restrictive Content Security Policy that blocks inline scripts, inline event handlers, and unnecessary outbound connections. Move existing inline JavaScript into a separate bundled file so nonces or hashes can be applied. 6. Add regression tests for payloads containing event handlers, SVG payloads, malformed types, and ``. 7. Treat all imported reports as untrusted, even if they are expected to have been generated locally. ]]>
