Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 050ed97

Browse files
committed
add node-serialize as a js/code-injection sink
1 parent 984194d commit 050ed97

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

javascript/ql/src/semmle/javascript/security/dataflow/CodeInjectionCustomizations.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,8 @@ module CodeInjection {
8686
|
8787
this = c.getArgument(index)
8888
)
89+
or
90+
this = DataFlow::moduleMember("node-serialize", "unserialize").getACall().getArgument(0)
8991
}
9092
}
9193

0 commit comments

Comments
 (0)