T08 · Insecure Dependencies
- Location
references/legacy-report-spec.md:352- Finding
Unpinned Remote JavaScript Dependency in Generated HTML Reports
- Content
View full analysis
Vulnerability Details
File Location:
references/legacy-report-spec.md, line 352
Vulnerability Type: Mutable third-party JavaScript loaded from a remote CDN
Risk Level: MediumComplete Code Snippet:
markdown **ECharts CDN引用:`https://cdn.jsdelivr.net/npm/echarts@5/dist/echarts.min.js`**Technical Analysis
The deep-report specification requires generated HTML reports to load ECharts as executable JavaScript from jsDelivr. The dependency uses the mutable major-version selector
@5instead of an exact, reviewed version. It also does not require Subresource Integrity verification.Consequently, the JavaScript executed by a report viewer may differ from the content available when the Skill was audited. A compromise of the package release process, npm distribution path, CDN infrastructure, or dependency resolution process could cause generated reports to execute substituted JavaScript.
This is classified as an insecure dependency rather than confirmed malicious remote payload behavior: the repository contains no evidence that the specified CDN currently serves malicious content. The risk arises from mutable external executable content and the absence of integrity controls.
Attack Path
- A user requests a report using the
deepformat. - The Agent follows the specification and generates HTML referencing
https://cdn.jsdelivr.net/npm/echarts@5/dist/echarts.min.js. - The user opens the generated report in a browser while network access is available.
- The browser resolves the mutable
@5selector and downloads JavaScript from the external CDN. - If the upstream package or CDN delivery path has been compromised, attacker-controlled JavaScript executes in the report's browser context.
Impact Assessment
Exploitation would grant the substituted script the privileges available to JavaScript in the generated report's browser context. It could:
- Read drug, clinical, transaction, and preliminary patent information rende ...[truncated 606 chars]
- A user requests a report using the
- Remediation
View remediation
Remediation Suggestions
- Prefer a locally vendored, reviewed ECharts build so generated reports do not depend on remote executable content.
- If CDN delivery is unavoidable, pin an exact immutable version rather than the mutable
@5selector. - Require a verified Subresource Integrity hash and
crossorigin="anonymous"on the script element. - Add a restrictive Content Security Policy that permits scripts only from explicitly approved sources and blocks unnecessary outbound connections.
- Record the exact dependency version, integrity hash, review date, and source in the report-generation specification.
- Consider generating static charts or sandboxing reports where confidentiality or offline review is required.
A hardened reference should follow this pattern, using an exact version and the verified hash for that exact artifact:
html <script src="https://cdn.jsdelivr.net/npm/echarts@EXACT_VERSION/dist/echarts.min.js" integrity="sha384-VERIFIED_HASH" crossorigin="anonymous"></script>
