T09 · Insecure Skill Coding Practices
- Location
assets/disclosure-guide.html:1259- Finding
DOM-Based Cross-Site Scripting in Disclosure Draft Rendering
- Content
View full analysis
`${title}
${body}
`).join(""); } ``` ### Technical Analysis Form values are read by `saveData()` and stored without sanitization in the `data` object. `renderSummary()` then interpolates those user-controlled values into an HTML template and assigns the result to the `innerHTML` property of the summary container. Because `innerHTML` parses its input as markup rather than plain text, an attacker-controlled field value can introduce arbitrary HTML elements and executable event-handler attributes. For example, a value such as: ```html``` will be parsed as an image element when the disclosure summary is generated. The failed image load invokes the injected `onerror` handler in the page context. The dynamic summary titles come from static dictionaries, but the `body` values include multiple directly editable fields, including the i ...[truncated 1812 chars]
- Remediation
View remediation
{ const article = document.createElement("article"); article.className = "summary-block"; const heading = document.createElement("h3"); heading.textContent = title; const paragraph = document.createElement("p"); paragraph.textContent = body; article.append(heading, paragraph); summary.appendChild(article); }); } ``` 3. If rich-text input becomes a product requirement, sanitize it with a maintained allowlist-based HTML sanitizer and prohibit scripts, event-handler attributes, dangerous URL schemes, SVG execution primitives, and embedded active content. 4. Add regression tests using payloads involving event handlers, malformed tags, SVG, MathML, and encoded markup. 5. Add a restrictive Content Security Policy as defense in depth. Prefer external JavaScript or a nonce/hash-based policy so that inline script execution can be disabled. 6. Review o ...[truncated 139 chars]
