From a6d728a66d54c61b66edf1376d7eb09cb690e64a Mon Sep 17 00:00:00 2001 From: Napalys Klicius Date: Wed, 17 Sep 2025 11:19:33 +0200 Subject: [PATCH 1/5] JS: Add test case with missing alert using `graphql` --- .../CWE-094/CodeInjection/graph-ql.js | 36 +++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js new file mode 100644 index 000000000000..e0cd0dd56096 --- /dev/null +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js @@ -0,0 +1,36 @@ +const express = require('express'); +const { graphql, buildSchema } = require('graphql'); + +const app = express(); +app.use(express.json()); + +const schema = buildSchema(` + type Query { + greet(name: String!): String + calc(expr: String!): String + } +`); + +const root = { + greet: ({ name }) => { + return `Hello, ${name}!`; + }, + calc: ({ expr }) => { + try { + return eval(expr).toString(); // $ MISSING: Alert[js/code-injection] + } catch (e) { + return `Error: ${e.message}`; + } + } +}; + +app.post('/graphql', async (req, res) => { + const { query, variables } = req.body; // $ MISSING: Source[js/code-injection] + const result = await graphql({ + schema, + source: query, + rootValue: root, + variableValues: variables + }); + res.json(result); +}); From 4282005e3289bac344f2cc0f3dd431e63351c403 Mon Sep 17 00:00:00 2001 From: Napalys Klicius Date: Wed, 17 Sep 2025 11:25:31 +0200 Subject: [PATCH 2/5] JS: Add summary model for `graphql`'s `rootValue` --- javascript/ql/lib/ext/graph-ql.model.yml | 6 ++++++ .../CWE-094/CodeInjection/CodeInjection.expected | 14 ++++++++++++++ .../HeuristicSourceCodeInjection.expected | 13 +++++++++++++ .../Security/CWE-094/CodeInjection/graph-ql.js | 4 ++-- 4 files changed, 35 insertions(+), 2 deletions(-) create mode 100644 javascript/ql/lib/ext/graph-ql.model.yml diff --git a/javascript/ql/lib/ext/graph-ql.model.yml b/javascript/ql/lib/ext/graph-ql.model.yml new file mode 100644 index 000000000000..4b441579e56d --- /dev/null +++ b/javascript/ql/lib/ext/graph-ql.model.yml @@ -0,0 +1,6 @@ +extensions: + - addsTo: + pack: codeql/javascript-all + extensible: summaryModel + data: + - ["graphql", "Member[graphql]", "Argument[0].Member[source]", "Argument[0].Member[rootValue].AnyMember.Parameter[0].AnyMember", "taint"] diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected index 8ddaba30fc8c..140e0295d43f 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected @@ -61,6 +61,7 @@ | fastify.js:107:23:107:31 | userInput | fastify.js:106:21:106:38 | request.query.code | fastify.js:107:23:107:31 | userInput | This code execution depends on a $@. | fastify.js:106:21:106:38 | request.query.code | user-provided value | | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:41 | request.query | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:41 | request.query | user-provided value | | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:51 | request ... plyCode | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:51 | request ... plyCode | user-provided value | +| graph-ql.js:20:19:20:22 | expr | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:20:19:20:22 | expr | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value | | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | This code execution depends on a $@. | module.js:9:16:9:29 | req.query.code | user-provided value | | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | This code execution depends on a $@. | module.js:11:17:11:30 | req.query.code | user-provided value | | react-native.js:8:32:8:38 | tainted | react-native.js:7:17:7:33 | req.param("code") | react-native.js:8:32:8:38 | tainted | This code execution depends on a $@. | react-native.js:7:17:7:33 | req.param("code") | user-provided value | @@ -154,6 +155,12 @@ edges | fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | | | fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | | | fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | | +| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | | +| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | | +| graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | | +| graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | | +| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | | @@ -288,6 +295,13 @@ nodes | fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code | | fastify.js:107:23:107:31 | userInput | semmle.label | userInput | | fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode | +| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:20:19:20:22 | expr | semmle.label | expr | +| graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } | +| graph-ql.js:28:11:28:15 | query | semmle.label | query | +| graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body | +| graph-ql.js:31:13:31:17 | query | semmle.label | query | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | | react-native.js:7:7:7:13 | tainted | semmle.label | tainted | diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected index db39855c5e5c..5acafe121672 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected @@ -55,6 +55,12 @@ edges | fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | | | fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | | | fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | | +| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | | +| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | | +| graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | | +| graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | | +| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | | @@ -191,6 +197,13 @@ nodes | fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code | | fastify.js:107:23:107:31 | userInput | semmle.label | userInput | | fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode | +| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:20:19:20:22 | expr | semmle.label | expr | +| graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } | +| graph-ql.js:28:11:28:15 | query | semmle.label | query | +| graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body | +| graph-ql.js:31:13:31:17 | query | semmle.label | query | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | | react-native.js:7:7:7:13 | tainted | semmle.label | tainted | diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js index e0cd0dd56096..46e4ea20e95c 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js @@ -17,7 +17,7 @@ const root = { }, calc: ({ expr }) => { try { - return eval(expr).toString(); // $ MISSING: Alert[js/code-injection] + return eval(expr).toString(); // $ Alert[js/code-injection] } catch (e) { return `Error: ${e.message}`; } @@ -25,7 +25,7 @@ const root = { }; app.post('/graphql', async (req, res) => { - const { query, variables } = req.body; // $ MISSING: Source[js/code-injection] + const { query, variables } = req.body; // $ Source[js/code-injection] const result = await graphql({ schema, source: query, From 6d461d6b506ea09ca458126f2b54d6cefd8fd77a Mon Sep 17 00:00:00 2001 From: Napalys Klicius Date: Wed, 17 Sep 2025 11:29:26 +0200 Subject: [PATCH 3/5] JS: Add change note --- javascript/ql/lib/change-notes/2025-09-17-graphql-enhance.md | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 javascript/ql/lib/change-notes/2025-09-17-graphql-enhance.md diff --git a/javascript/ql/lib/change-notes/2025-09-17-graphql-enhance.md b/javascript/ql/lib/change-notes/2025-09-17-graphql-enhance.md new file mode 100644 index 000000000000..cb0b886a6f75 --- /dev/null +++ b/javascript/ql/lib/change-notes/2025-09-17-graphql-enhance.md @@ -0,0 +1,4 @@ +--- +category: minorAnalysis +--- +* Support for the [graphql](https://www.npmjs.com/package/graphql) library has been improved. Data flow from GraphQL query sources and variables to resolver function parameters is now tracked. From 6c18b4de40a5caad9cc80395604f96e9522106e6 Mon Sep 17 00:00:00 2001 From: Napalys Klicius Date: Wed, 17 Sep 2025 12:21:21 +0200 Subject: [PATCH 4/5] JS: Add test case for graph ql variableValues injection --- .../CWE-094/CodeInjection/graph-ql.js | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js index 46e4ea20e95c..f33d6c7f4d00 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js @@ -33,4 +33,24 @@ app.post('/graphql', async (req, res) => { variableValues: variables }); res.json(result); + + const root1 = { + greet: ({ name, title }) => { + return eval(name + title).toString(); // $ MISSING: Alert[js/code-injection] + } + }; + graphql({ + schema: buildSchema(` + type Query { + greet(name: String!, title: String): String + } + `), + source: ` + query GreetUser($name: String!, $title: String) { + greet(name: $name, title: $title) + } + `, + rootValue: root1, + variableValues: variables + }); }); From 7affcf40c29fc98f75301c0b6313af505eff1a54 Mon Sep 17 00:00:00 2001 From: Napalys Klicius Date: Wed, 17 Sep 2025 12:24:14 +0200 Subject: [PATCH 5/5] JS: Add `variableValues` to the previous summaryModel to enchance the flow. --- javascript/ql/lib/ext/graph-ql.model.yml | 2 +- .../CodeInjection/CodeInjection.expected | 27 ++++++++++++++++--- .../HeuristicSourceCodeInjection.expected | 26 +++++++++++++++--- .../CWE-094/CodeInjection/graph-ql.js | 2 +- 4 files changed, 49 insertions(+), 8 deletions(-) diff --git a/javascript/ql/lib/ext/graph-ql.model.yml b/javascript/ql/lib/ext/graph-ql.model.yml index 4b441579e56d..08233d1135da 100644 --- a/javascript/ql/lib/ext/graph-ql.model.yml +++ b/javascript/ql/lib/ext/graph-ql.model.yml @@ -3,4 +3,4 @@ extensions: pack: codeql/javascript-all extensible: summaryModel data: - - ["graphql", "Member[graphql]", "Argument[0].Member[source]", "Argument[0].Member[rootValue].AnyMember.Parameter[0].AnyMember", "taint"] + - ["graphql", "Member[graphql]", "Argument[0].Member[source,variableValues]", "Argument[0].Member[rootValue].AnyMember.Parameter[0]", "taint"] diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected index 140e0295d43f..3f5d8abed8a4 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/CodeInjection.expected @@ -62,6 +62,7 @@ | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:41 | request.query | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:41 | request.query | user-provided value | | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:51 | request ... plyCode | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:51 | request ... plyCode | user-provided value | | graph-ql.js:20:19:20:22 | expr | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:20:19:20:22 | expr | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value | +| graph-ql.js:39:19:39:30 | name + title | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:39:19:39:30 | name + title | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value | | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | This code execution depends on a $@. | module.js:9:16:9:29 | req.query.code | user-provided value | | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | This code execution depends on a $@. | module.js:11:17:11:30 | req.query.code | user-provided value | | react-native.js:8:32:8:38 | tainted | react-native.js:7:17:7:33 | req.param("code") | react-native.js:8:32:8:38 | tainted | This code execution depends on a $@. | react-native.js:7:17:7:33 | req.param("code") | user-provided value | @@ -155,12 +156,23 @@ edges | fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | | | fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | | | fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | | -| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:18:10:18:17 | { expr } | graph-ql.js:18:12:18:15 | expr | provenance | | | graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | | | graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | | +| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:18:28:26 | variables | provenance | | | graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:33:21:33:29 | variables | provenance | | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:54:21:54:29 | variables | provenance | | | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | | -| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:10:18:17 | { expr } | provenance | | +| graph-ql.js:33:21:33:29 | variables | graph-ql.js:18:10:18:17 | { expr } | provenance | | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:15:38:18 | name | provenance | | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:21:38:25 | title | provenance | | +| graph-ql.js:38:15:38:18 | name | graph-ql.js:39:19:39:22 | name | provenance | | +| graph-ql.js:38:21:38:25 | title | graph-ql.js:39:26:39:30 | title | provenance | | +| graph-ql.js:39:19:39:22 | name | graph-ql.js:39:19:39:30 | name + title | provenance | | +| graph-ql.js:39:26:39:30 | title | graph-ql.js:39:19:39:30 | name + title | provenance | | +| graph-ql.js:54:21:54:29 | variables | graph-ql.js:38:13:38:27 | { name, title } | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | | @@ -295,13 +307,22 @@ nodes | fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code | | fastify.js:107:23:107:31 | userInput | semmle.label | userInput | | fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode | -| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:18:10:18:17 | { expr } | semmle.label | { expr } | | graph-ql.js:18:12:18:15 | expr | semmle.label | expr | | graph-ql.js:20:19:20:22 | expr | semmle.label | expr | | graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } | | graph-ql.js:28:11:28:15 | query | semmle.label | query | +| graph-ql.js:28:18:28:26 | variables | semmle.label | variables | | graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body | | graph-ql.js:31:13:31:17 | query | semmle.label | query | +| graph-ql.js:33:21:33:29 | variables | semmle.label | variables | +| graph-ql.js:38:13:38:27 | { name, title } | semmle.label | { name, title } | +| graph-ql.js:38:15:38:18 | name | semmle.label | name | +| graph-ql.js:38:21:38:25 | title | semmle.label | title | +| graph-ql.js:39:19:39:22 | name | semmle.label | name | +| graph-ql.js:39:19:39:30 | name + title | semmle.label | name + title | +| graph-ql.js:39:26:39:30 | title | semmle.label | title | +| graph-ql.js:54:21:54:29 | variables | semmle.label | variables | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | | react-native.js:7:7:7:13 | tainted | semmle.label | tainted | diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected index 5acafe121672..3d4022d8fb6a 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/HeuristicSourceCodeInjection.expected @@ -55,12 +55,23 @@ edges | fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | | | fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | | | fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | | -| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:18:10:18:17 | { expr } | graph-ql.js:18:12:18:15 | expr | provenance | | | graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | | | graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | | +| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:18:28:26 | variables | provenance | | | graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:33:21:33:29 | variables | provenance | | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:54:21:54:29 | variables | provenance | | | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | | -| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | | +| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:10:18:17 | { expr } | provenance | | +| graph-ql.js:33:21:33:29 | variables | graph-ql.js:18:10:18:17 | { expr } | provenance | | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:15:38:18 | name | provenance | | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:21:38:25 | title | provenance | | +| graph-ql.js:38:15:38:18 | name | graph-ql.js:39:19:39:22 | name | provenance | | +| graph-ql.js:38:21:38:25 | title | graph-ql.js:39:26:39:30 | title | provenance | | +| graph-ql.js:39:19:39:22 | name | graph-ql.js:39:19:39:30 | name + title | provenance | | +| graph-ql.js:39:26:39:30 | title | graph-ql.js:39:19:39:30 | name + title | provenance | | +| graph-ql.js:54:21:54:29 | variables | graph-ql.js:38:13:38:27 | { name, title } | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | | react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | | @@ -197,13 +208,22 @@ nodes | fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code | | fastify.js:107:23:107:31 | userInput | semmle.label | userInput | | fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode | -| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | +| graph-ql.js:18:10:18:17 | { expr } | semmle.label | { expr } | | graph-ql.js:18:12:18:15 | expr | semmle.label | expr | | graph-ql.js:20:19:20:22 | expr | semmle.label | expr | | graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } | | graph-ql.js:28:11:28:15 | query | semmle.label | query | +| graph-ql.js:28:18:28:26 | variables | semmle.label | variables | | graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body | | graph-ql.js:31:13:31:17 | query | semmle.label | query | +| graph-ql.js:33:21:33:29 | variables | semmle.label | variables | +| graph-ql.js:38:13:38:27 | { name, title } | semmle.label | { name, title } | +| graph-ql.js:38:15:38:18 | name | semmle.label | name | +| graph-ql.js:38:21:38:25 | title | semmle.label | title | +| graph-ql.js:39:19:39:22 | name | semmle.label | name | +| graph-ql.js:39:19:39:30 | name + title | semmle.label | name + title | +| graph-ql.js:39:26:39:30 | title | semmle.label | title | +| graph-ql.js:54:21:54:29 | variables | semmle.label | variables | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | | react-native.js:7:7:7:13 | tainted | semmle.label | tainted | diff --git a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js index f33d6c7f4d00..f68f47cf3acd 100644 --- a/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js +++ b/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/graph-ql.js @@ -36,7 +36,7 @@ app.post('/graphql', async (req, res) => { const root1 = { greet: ({ name, title }) => { - return eval(name + title).toString(); // $ MISSING: Alert[js/code-injection] + return eval(name + title).toString(); // $ Alert[js/code-injection] } }; graphql({