CodeQL library for JavaScript
Search

Module CommandInjection

Provides a taint tracking configuration for reasoning about command-injection vulnerabilities (CWE-078).

Note, for performance reasons: only import this file if CommandInjection::Configuration is needed, otherwise CommandInjectionCustomizations should be imported instead.

Import path

import semmle.javascript.security.dataflow.CommandInjection

Imports

javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Modules