T09 · Insecure Skill Coding Practices
- Location
scripts/create_static_report_html.py:33- Finding
Stored JavaScript Injection Through Unsafe JSON Embedding
- Content
View full analysis
str: params = report_data.get("params") or {} seed = ( f" window.INITIAL_REPORT_PARAMS = {json.dumps({'date_from': params.get('date_from'), 'date_to': params.get('date_to')}, ensure_ascii=False)};\n" f" window.INITIAL_REPORT_DATA = {json.dumps(report_data, ensure_ascii=False)};\n" ) if MARKER not in html: raise RuntimeError("Could not find init marker in template") html = html.replace(MARKER, seed + MARKER, 1) ``` The equivalent vulnerable construction in `scripts/create_seeded_screening_platform.py` is: ```python def inject_initial_data(index_path: Path, data: dict, date_from: str, date_to: str) -> None: html = index_path.read_text(encoding="utf-8") seed = ( f" window.INITIAL_REPORT_PARAMS = {json.dumps({'date_from': date_from, 'date_to': date_to}, ensure_ascii=False)};\n" f" window.INITIAL_REPORT_DATA = {json.dumps(data, ensure_ascii=False)};\n" ) if MARKER not in html: raise RuntimeError("Could not find init marker in index.html") html = html.replace(MARKER, seed + MARKER, 1) index_path.write_text(html, encoding="utf-8") ``` The equivalent vulnerable construction in `scripts/generate_seeded_platform.py` is: ```python html = index_path.read_text(encoding="utf-8") seed = ( f" window.INITIAL_REPORT_PARAMS = {json.dumps({'date_from': args.date_from, 'date_to': args.date_to}, ensure_ascii=False)};\n" f" window.INITIAL_REPORT_DATA = {json.dumps(data, ensure_ascii=False)};\n" ) if MARKER not in html: raise SystemExit("Could not ...[truncated 2426 chars]- Remediation
View remediation
``` Populate it with JSON that is safe for HTML text context, and then parse its `textContent`: ```javascript const reportData = JSON.parse( document.getElementById("initial-report-data").textContent ); ``` 3. At minimum, encode HTML-significant characters before insertion: ```python safe_json = ( json.dumps(report_data, ensure_ascii=False) .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("&", "\\u0026") ) ``` 4. Apply the same shared safe-serialization function in all three generation scripts. 5. Validate the report structure and accepted field types before generating HTML. 6. Add regression tests using values containing: ```text
