T09 · Insecure Skill Coding Practices
- Location
scripts/generate_portal.py:69- Finding
Stored HTML and JavaScript Injection in Generated Portal Pages
- Content
View full analysis
str: if not news_list: return '暂无相关新闻
' cards = [] for n in news_list[:8]: url = n.get("url") or "#" title = n.get("title", "(无标题)") date = n.get("date", "") source = n.get("source", "") summary = n.get("summary", n.get("content", ""))[:200] cards.append(f""" """) ``` The same direct interpolation pattern is used for patent records, company data, technology tags, events, the portal keyword, and the date range. ### Technical Analysis The generator inserts values obtained from portal JSON, user input, and external search results directly into HTML f-strings. It applies neither HTML escaping nor URL-scheme validation. Text values can terminate their intended element and inject arbitrary markup. For example, a malicious title or summary containing: ```html``` would be writte ...[truncated 1722 chars]
- Remediation
View remediation
