T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:1136- Finding
Stored HTML and JavaScript Injection Through Unescaped Report Parameters
- Content
View full analysis
str: brand = f"{ctx['company']} 产业链战略报告 · {ctx['report_id']}" pages = [ build_p1(ctx), build_p2(ctx, brand), build_p3(ctx, brand), build_p4(ctx, brand), build_p5(ctx, brand), build_p6(ctx, brand), build_p7(ctx, brand), build_p8(ctx, brand), build_p9(ctx, brand), build_p10(ctx, brand), ] html = f""" {ctx['company']} 产业链战略报告 · {ctx['report_id']} {WHITEPAPER_CSS} {''.join(pages)} """ if output_path: Path(output_path).parent.mkdir(parents=True, exist_ok=True) with open(output_path, "w", encoding="utf-8") as f: f.write(html) ``` The affected values originate from command-line arguments: ```python parser = argparse.ArgumentParser(description="企业决策者产业链战略报告系统 v2.0") parser.add_argument("--company", required=True, help="目标企业名称") parser.add_argument("--chain", default="", help="产业链名称(可选)") ``` Additional unescaped interpolation occurs in page construction: ```python{ctx["company"]}
产业链战略研判报告{ctx["company"].upper()} · {ctx["chain"].upper()} INDUSTRY CHAIN STRATEGY REPORT``` ### Technical Analysis The `--company` and `--chain` command-line values are copied into the rendering context and interpolated directly into generated HTML. No context-sensitive HTML escaping, sanitization, or safe templating mechanism is applied. ...[truncated 1773 chars]- Remediation
View remediation
