T09 · Insecure Skill Coding Practices
- Location
scripts/plot_interactive.py:169- Finding
Stored HTML Injection Through Unescaped Source Filename
- Content
View full analysis
🗺️ {source}
Distance: {stats['total_distance_km']:.2f} km Points: {stats['point_count']} Elev Gain: +{stats['elevation_gain_m']:.0f} m Elev Loss: -{stats['elevation_loss_m']:.0f} m Max Elev: {stats['max_elevation_m']:.0f} m Min Elev: {stats['min_elevation_m']:.0f} m Avg Elev: {stats['avg_elevation_m']:.0f} m""" # Get the raw HTML html = m.get_root().render() # Insert stats panel after body_idx = html.find("") if body_idx != -1: insert_pos = body_idx + len("") html = html[:insert_pos] + stats_html + html[insert_pos:] ``` ### Technical Analysis The `source_file` property is read from an input JSON document and reduced to a basename, but it is not HTML-escaped. The resulting `source` value is interpolated directly into `stats_html`, which is then inserted into the generated HTML document as raw markup. `Path(...).name` does not sanitize HTML metacharacters. An attacker able to provide or modify the input JSON can use a value such as: ```json { "source_file": "" } ``` When the generated map is opened in a browser, the inject ...[truncated 1369 chars]
- Remediation
View remediation
`, `"`, `'`, `&`, closing tags, and `
