flawopen.com/Cross-Site Scripting/Python

Cross-Site Scripting in Python

Élevée CWE-79 Draft — pending review
Language: English Português (Brasil) Español Français Deutsch Русский 简体中文 日本語 हिन्दी 한국어 Bahasa Indonesia
Explication simple

Imagine a guestbook where a visitor writes a note containing hidden script tags that execute in the browser of the next person who opens the page.

Termes clés sur cette page
output encoding
Converting special markup characters into safe entities so browsers display them as text rather than script.

Ce qui se passe

Cross-Site Scripting in Python occurs when untrusted input is formatted directly into HTML strings instead of using template auto-escaping.

Impact dans le monde réel

In 2005, the Samy XSS worm infected over 1 million user profiles on MySpace in under 20 hours, forcing the platform offline.

Documented historical AppSec case study.

Vulnérable vs corrigé

VULNERABLE
# username inserted with no escaping
@app.route("/welcome")
def welcome():
  name = request.args.get("name")
  return f"
Welcome, {name}
"
FIXED
# Jinja2 template auto-escapes by default
@app.route("/welcome")
def welcome():
  name = request.args.get("name")
  return render_template("welcome.html", name=name)

Pourquoi la correction fonctionne

Template engines like Jinja2 and Django auto-escape HTML entities by default, rendering markup inert.

Pièges spécifiques au langage

Django mark_safe() and Jinja2 | safe

Marking untrusted data as safe disables all escaping, reopening stored and reflected XSS.

f-strings bypass templates

Python f-strings execute before template rendering, bypassing auto-escaping entirely.

Idées reçues courantes

"f-strings are safe inside templates"

f-strings evaluate before template escaping happens, leaving user input completely raw.

Comment vérifier si vous êtes concerné

grep -rn "render_template_string(.*f\"" --include="*.py" . grep -rn "mark_safe(" --include="*.py" .
Run Bandit with rule B701 (jinja2_autoescape_false) in CI to catch unescaped templates automatically.

Liste de contrôle de prévention

Foire aux questions

Does Flask escape by default?

Yes, for .html, .htm, and .xml template extensions rendered with render_template().

Références

Voir aussi : SQL Injection Command InjectionPath Traversal