We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 4a691b7 commit 478e32cCopy full SHA for 478e32c
javascript/ql/lib/semmle/javascript/security/dataflow/TaintedPathCustomizations.qll
@@ -892,10 +892,13 @@ module TaintedPath {
892
TaintTracking::uriStep(node1, node2)
893
or
894
exists(DataFlow::CallNode decode |
895
- decode.getCalleeName() = "decodeURIComponent" or
896
- decode.getCalleeName() = "decodeURI" or
897
- decode.getCalleeName() = "escape" or
898
- decode.getCalleeName() = "unescape"
+ decode =
+ DataFlow::globalVarRef([
+ "decodeURIComponent",
+ "decodeURI",
899
+ "escape",
900
+ "unescape"
901
+ ]).getACall()
902
|
903
node1 = decode.getArgument(0) and
904
node2 = decode
0 commit comments