Skip to content

Commit 0d598c4

Browse files
committed
JS: Fix observed FPs in UnsafeJQueryPlugin
1 parent b321151 commit 0d598c4

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

javascript/ql/lib/semmle/javascript/security/dataflow/UnsafeJQueryPluginQuery.qll

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,9 @@ class Configuration extends TaintTracking::Configuration {
2323
node instanceof DomBasedXss::Sanitizer
2424
or
2525
node instanceof Sanitizer
26+
or
27+
// Plugins usually do `$(this)` to coerce an existing DOM element to a jQuery object.
28+
node instanceof DataFlow::ThisNode
2629
}
2730

2831
override predicate isAdditionalTaintStep(DataFlow::Node src, DataFlow::Node sink) {

0 commit comments

Comments
 (0)