Skip to content

Commit 5ce9e0d

Browse files
Update javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql
Co-authored-by: Erik Krogh Kristensen <[email protected]>
1 parent 122354a commit 5ce9e0d

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -58,5 +58,6 @@ class SSTINunjucksSink extends ServerSideTemplateInjectionSink {
5858

5959
from DataFlow::PathNode source, DataFlow::PathNode sink, ServerSideTemplateInjectionConfiguration c
6060
where c.hasFlowPath(source, sink)
61-
select sink.getNode(), source, sink, "$@ flows to here and unsafely used as part of rendered template",
62-
source.getNode(), "User-provided value"
61+
select sink.getNode(), source, sink,
62+
"$@ flows to here and unsafely used as part of rendered template", source.getNode(),
63+
"User-provided value"

0 commit comments

Comments
 (0)