T08 · Insecure Dependencies
- Location
references/html_skeleton_template.html:7- Finding
Third-Party JavaScript Loaded Without Integrity Verification
- Content
View full analysis
``` ### Technical Analysis The HTML template loads executable Chart.js code directly from the jsDelivr content delivery network. Although the dependency is pinned to version `4.4.0`, the script element does not include a Subresource Integrity hash. The template also does not define a restrictive Content Security Policy. Without integrity verification, the browser cannot confirm that the downloaded JavaScript matches a previously reviewed artifact. If the CDN, its upstream package, or the delivery path supplies modified content, that content will execute in the report's browser context. The Python scripts do not retrieve or execute this dependency; exposure occurs when a generated HTML report is opened in a browser with network connectivity. ### Attack Path 1. A report author copies or generates a report from `html_skeleton_template.html`. 2. The report retains the external Chart.js script reference. 3. A user opens the report while connected to the Internet. 4. The browser requests the script from jsDelivr. 5. An attacker who has compromised the relevant CDN or upstream delivery mechanism returns modified JavaScript. 6. The browser executes the modified script because no integrity hash is available to detect the change. 7. The script can inspect or alter the report DOM and initiate outbound browser requests, subject to the browser's origin and security restrictions. This path depends on compromise or malicious modification of the third-party delivery chain; no such compromise is demonstrated in the audited project. ### Impact Assessment A successful supply-chain attack could: - Read patent, market, and competitive intelligence displayed in the repo ...[truncated 578 chars]- Remediation
View remediation
``` - Do not use a placeholder hash in production. Verify it independently against the exact downloaded artifact. 3. **Apply a restrictive Content Security Policy** - Limit `script-src` to trusted local resources or the precise required CDN. - Restrict outbound connections with `connect-src`. - Avoid allowing `unsafe-eval` or unrestricted script origins. - When reports are hosted, prefer delivering the policy as an HTTP response header. 4. **Retain the existing offline fallback** - Preserve the `` tables. - If external Chart.js loading fails integrity validation or is unavailable, automatically expose the static fallback without attempting alternate untrusted sources. 5. **Document network behavior** - Inform report authors that retaining the CDN reference causes a network request when the report is opened. - Provide an offline-only build option for confidential reports. ]]>
