T09 · Insecure Skill Coding Practices
- Location
scripts/convert_deck.py:585- Finding
Unvalidated accent color permits script injection into generated presentations
- Content
View full analysis
` template in `generate_html()` **Vulnerability Type**: HTML/CSS template injection leading to arbitrary JavaScript execution **Risk Level**: Medium ### Vulnerable Code ```python parser.add_argument("--color", "-c", default="#1a73e8", help="Accent color (hex)") ``` ```python html = generate_html(slides, title, args.color) ``` The value is inserted directly into the generated HTML's inline style sheet: ```python .progress-fill {{ height: 100%; background: {accent_color}; width: 0%; transition: width 0.3s ease; }} ``` Other CSS rules also interpolate the same unvalidated value. ### Technical Analysis The `--color` command-line argument is described as a hexadecimal color, but the implementation does not validate that it is a color. `accent_color` is inserted directly into a raw `` element without contextual escaping. An attacker who can influence this parameter can supply markup that terminates the style element and creates a script element, for example: ```text ``` HTML character escaping is not applied to this value, and ordinary HTML escaping alone would not be a sufficient substitute for strict color validation. When the generated presentation is opened, the injected script executes in the presentation's browser context. This is especially relevant if another application or agent exposes the converter through a web interface, job queue, automation pipeline, or other mechanism where the color parameter can be supplied by an untrusted party. The separately flagged Base64 behavior is not itself evidence of exfiltration. The script only Base64-encodes images extracted from the selected deck and embeds them in local `data:` URIs, which is necessary for the declared self-contained HTML functionality. No network tra ...[truncated 1746 chars]- Remediation
View remediation
`, `
