Thanks to visit codestin.com Credit goes to github.com
We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
open
1 parent a885e61 commit df89739Copy full SHA for df89739
1 file changed
javascript/ql/test/query-tests/Security/CWE-022/TaintedPath/open.js
@@ -0,0 +1,11 @@
1
+import open, {openApp, apps} from 'open';
2
+
3
+const express = require('express');
4
+const app = express();
5
6
+app.get('/open', (req, res) => {
7
+ const file = req.query.file; // $ MISSING: Source
8
9
+ open(file); // $ MISSING: Alert
10
+ openApp(file); // $ MISSING: Alert
11
+});
0 commit comments