T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:190- Finding
Stored HTML Injection and Unsafe Hyperlink Schemes in Generated Reports
- Content
View full analysis
{pn}' ``` Representative unescaped workbook fields are also inserted directly into HTML: ```python for i, r in cat_patents.iterrows(): pn = str(r["公开(公告)号"]) ptitle = str(r["标题"]) applicant = str(r.get("[标]当前申请(专利权)人", "N/A")) status = str(r.get("简单法律状态", "N/A")) patsnap = str(r.get("Patsnap专利标题", "-")) if patsnap == "nan": patsnap = "-" A('') A(img_html(pn, pn_to_b64, "patent-img-sm")) A(f'') ``` ### Technical Analysis The report generator constructs HTML through direct string interpolation. Values originating from Excel cells, workbook hyperlinks, command-line arguments, and executable content configurations are not HTML-escaped before being inserted into element bodies or attributes. This creates two related attack surfaces: 1. **HTML or script injection:** A malicious patent title, applicant, legal status, summary, category, or other text field can contain HTML markup. When the generated report is opened, the browser interprets that value as markup rather than plain text. 2. **Unsafe URI injection:** Workbook hyperlinks and configured news URLs are inserted directly into `href` attributes without valid ...[truncated 1785 chars]{pn_link(pn, pn_to_url)}') A(f'{ptitle}') A(f'{patsnap}') A(f'{status_tag(status)}{short_name(applicant, company_short_map)}{catname}') A('- Remediation
View remediation
``` 8. Add regression tests using malicious titles, applicants, statuses, summaries, and hyperlinks to verify that payloads are rendered as plain text and dangerous URLs are rejected. ]]>
