T09 · Insecure Skill Coding Practices
- Location
scripts/generate_h5_report.py:90- Finding
Stored HTML Injection Through Untrusted News Data
- Content
View full analysis
' + news['title'] + '\n' if news.get('picture'): html_content += '\n' html_content += '
' + news['abstract'] + '\n' html_content += '\n' html_content += ' ' + news['source'] + '\n' html_content += ' Read more →\n' html_content += '\n' ``` The displayed English text in this excerpt is a translation of the corresponding user-interface literals; the vulnerable concatenation operations are unchanged. ### Technical Analysis The generator directly concatenates the externally supplied `title`, `picture`, `abstract`, `source`, and `url` fields into HTML. It does not apply context-sensitive HTML escaping or validate URL schemes. The data originates from the remote news API and is persisted in `data/daily_report.json`. Consequently, the application crosses a trust boundary when it treats those fields as safe markup. Possible payload classes include: - A title or abstract containing an HTML element with an event handler. - A picture value containing a quotation mark that terminates the `src` attribute and injects another attribute. - A URL using a dangerous scheme such as `javascript:`. - Markup that creates deceptive forms, overlays, or redirects within the generated report. The report also lacks a restrictive Content Security Policy that could provide defense in depth. ### Attack Path 1. An attacker compromises, controls, or otherwise influences a response returned by the conf ...[truncated 1191 chars]- Remediation
View remediation
