Skip to content

Commit 3a4ea82

Browse files
Update javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql
Co-authored-by: Erik Krogh Kristensen <[email protected]>
1 parent 8310c96 commit 3a4ea82

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,11 +25,11 @@ abstract class ServerSideTemplateInjectionSink extends DataFlow::Node { }
2525

2626
class SSTIPugSink extends ServerSideTemplateInjectionSink {
2727
SSTIPugSink() {
28-
exists(CallNode compile, ModuleImportNode renderImport, Node sink |
28+
exists(CallNode compile, ModuleImportNode renderImport |
2929
renderImport = moduleImport(["pug", "jade"]) and
3030
(
3131
compile = renderImport.getAMemberCall("compile") and
32-
sink.getStartLine() != sink.getASuccessor().getStartLine()
32+
exists(compile.getACall())
3333
or
3434
compile = renderImport.getAMemberCall("render")
3535
) and

0 commit comments

Comments
 (0)