We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 3f66c04 commit 3e3372bCopy full SHA for 3e3372b
javascript/ql/src/semmle/javascript/HtmlSanitizers.qll
@@ -48,6 +48,11 @@ private class DefaultHtmlSanitizerCall extends HtmlSanitizerCall {
48
or
49
callee = LodashUnderscore::member("escape")
50
51
+ exists(DataFlow::PropRead read | read = callee |
52
+ read.getPropertyName() = "sanitize" and
53
+ read.getBase().asExpr().(VarAccess).getName() = "DOMPurify"
54
+ )
55
+ or
56
exists(string name | name = "encode" or name = "encodeNonUTF" |
57
callee =
58
DataFlow::moduleMember("html-entities", _).getAnInstantiation().getAPropertyRead(name) or
0 commit comments