T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_data.py:140- Finding
Stored HTML Injection in Generated Analysis Reports
- Content
View full analysis
Generated: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')}Source: {self.input_file}
Summary
Total Records: {self.results.get('basic_stats', {}).get('count', 'N/A')}
Columns: {', '.join(map(str, self.results.get('basic_stats', {}).get('columns', [])))}
Grouped Analysis
""" # Add grouped data grouped = self.results.get('grouped', {}) for key, value in grouped.items(): html += f" \n" ``` ### Technical Analysis The report generator directly interpolates the input path, dataset column names, group keys, and grouped values into an HTML document without applying context-appropriate HTML escaping. An attacker who controls a CSV, Excel, or JSON dataset can place HTML markup or JavaScript-capable elements in a column name or grouped field value. When the analyzer generates an HTML report, the supplied markup is stored verbatim in the output document. It can then be interpreted by a browser when the report is opened. For example, a malicious grouping value could contain an image element with an error event handler. Because the value is inserted directly between `Group Count {key} {value} ` tags, the browser treats it as markup rather than plain text. The input filename is also inserted without escaping. This provides another injection surface where an attacker can influence the filename used to deliver a dataset, subject to filesystem naming restrictions. ### Attack Path 1. An attacker creates or modifies a supported dataset. 2. The attacker inserts malicious HTML into a column name or a ...[truncated 1265 chars] - Remediation
View remediation
{safe_key}{safe_value}\n" ``` Additional hardening should include: 1. Use a template engine with automatic HTML escaping instead of assembling documents through string concatenation. 2. Escape values according to their exact output context, including text nodes and attributes. 3. Consider adding a restrictive Content Security Policy to generated reports, such as disallowing inline scripts and remote content. 4. Add regression tests containing script elements, event-handler attributes, malformed tags, encoded payloads, and malicious column names. 5. Treat filenames and filesystem paths as untrusted display values and escape them as well. ]]>
