T08 · Insecure Dependencies
- Location
references/html-report-template-spec.md:13- Finding
Unprotected Third-Party JavaScript Dependency in Generated HTML Reports
- Content
View full analysis
Vulnerability Details
File Location:
references/html-report-template-spec.md, line 13
Vulnerability Type: Third-party JavaScript supply-chain exposure
Risk Level: MediumComplete Code Snippet:
markdown - **Chart library**: ECharts 5.4.3 (CDN: `https://cdn.jsdelivr.net/npm/echarts@5.4.3/dist/echarts.min.js`)Technical Analysis
The report template requires generated HTML reports to load ECharts as executable JavaScript from the third-party
cdn.jsdelivr.netinfrastructure. Although the URL pins ECharts to version 5.4.3, the specification does not require Subresource Integrity, a locally reviewed copy, or a restrictive Content Security Policy.Version pinning prevents normal semantic-version drift but does not cryptographically verify the retrieved file. If the CDN, upstream artifact, DNS resolution path, or another trusted distribution component is compromised, the browser could receive modified JavaScript. The modified payload would execute when a recipient opens the generated report.
This also conflicts with the Skill's description of the HTML output as fully self-contained because the report remains dependent on an external runtime resource.
Attack Path
- The Skill generates an HTML report according to the template specification.
- The generated report references the prescribed ECharts file on
cdn.jsdelivr.net. - A recipient opens the report while network access is available.
- The browser retrieves and executes the remote JavaScript without validating an SRI digest.
- If the dependency or its delivery channel has been compromised, attacker-controlled JavaScript executes in the report's browser context.
- The malicious script can inspect or modify report content, falsify charts or conclusions, and attempt to transmit accessible information through outbound network requests.
Impact Assessment
Exploitation provides JavaScript execution in the browser context of the ...[truncated 623 chars]
- Remediation
View remediation
Remediation Suggestions
- Bundle a reviewed ECharts distribution directly into each generated HTML report so that the output is genuinely self-contained.
- If an external CDN must be used, require a verified
integrityattribute containing the correct cryptographic digest and setcrossorigin="anonymous". - Pin the dependency by immutable content digest rather than relying only on a versioned URL.
- Add a restrictive Content Security Policy. Limit
script-srcto explicitly trusted sources and restrictconnect-srcto prevent unauthorized data transmission. - Maintain a documented dependency-update process that verifies upstream release provenance, computes new integrity hashes, and reviews security advisories before changing versions.
- Support offline rendering and fail safely if dependency verification fails; do not fall back to an unverified source.
- Update the template specification to make these controls mandatory for every generated HTML report.
