CodeQL library for Java/Kotlin
codeql/java-all 1.1.2-dev (changelog, source)
Search

Predicate uncontrolledStringBuilderQuery

A query built with a StringBuilder, where one of the items appended is uncontrolled.

Import path

import semmle.code.java.security.SqlConcatenatedLib
predicate uncontrolledStringBuilderQuery(StringBuilderVar sbv, Expr uncontrolled)