T09 · Insecure Skill Coding Practices
- Location
scripts/run_monitor.py:116- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
{p.get('pn','')}{p.get('title','')}{p.get('year','')}" for p in org_patents ) new_rows = "".join( f"{p.get('pn','')}{p.get('title','')}{p.get('org','')}{p.get('date','')}" for p in new_patents ) ``` The same unsafe interpolation pattern is used for inventor names, organizations, notes, company names, dates, and other JSON-derived values elsewhere in `generate_html_report()`. ### Technical Analysis The report generator reads JSON data from a path supplied through `--data` or the `MONITOR_DATA_JSON` environment variable. Values from this JSON file are inserted directly into an HTML document using Python formatted strings. No HTML escaping or sanitization is applied before fields such as patent titles, inventor names, organizations, notes, publication numbers, dates, or the company name are placed into HTML markup. Consequently, an input value containing HTML elements can terminate the intended markup and introduce attacker-controlled elements or JavaScript. For example, a malicious patent title could contain: ```html ``` The project includes `references/data_schema.json`, but neither report-generation path validates input against that schema. Moreover, the schema only constrains these fields to strings and would not, by itself, prevent HTML injection. ### Attack Path 1. An attacker gains influence over data included in the monitor JSON. Potential sources include a manually supplied JSON file or untrusted text propagate ...[truncated 1603 chars]- Remediation
View remediation
" f"{safe_text(p.get('pn'))}" f"{safe_text(p.get('title'))}" f"{safe_text(p.get('year'))}" "" for p in org_patents ) ``` Apply the same protection to `company`, `report_date`, `monitor_start`, `monitor_end`, `name`, `new_org`, `notes`, and all patent properties. 2. **Use an auto-escaping template engine** Replace large formatted HTML strings with a template engine such as Jinja2 configured with HTML auto-escaping. Do not mark upstream content as safe unless it has passed a narrowly defined sanitizer. 3. **Validate the JSON input** Validate data against `references/data_schema.json` before rendering. Add constraints for expected date formats, maximum string lengths, array sizes, and permitted object properties. Validation provides defense in depth but does not replace output encoding. 4. **Add a restrictive Content Security Policy** Include a policy suitable for a standalone report, for example: ```html ``` This reduces the effect of an escaping regression by blocking scripts, external frames, and network-loaded resources. 5. **Add security regression tests** Generate reports using payloads containing `
