CodeQL library for JavaScript/TypeScript
codeql/javascript-all 0.8.14 (changelog, source)
Search

Module UnsafeHtmlConstructionQuery

Provides a taint-tracking configuration for reasoning about unsafe HTML constructed from library input vulnerabilities.

Import path

import semmle.javascript.security.dataflow.UnsafeHtmlConstructionQuery

Imports

TaintedObject

Provides methods for reasoning about the flow of deeply tainted objects, such as JSON objects parsed from user-controlled data.

UnsafeHtmlConstruction

Module containing sources, sinks, and sanitizers for unsafe HTML constructed from library input.

javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Classes

Configuration

A taint-tracking configuration for reasoning about unsafe HTML constructed from library input vulnerabilities.

Aliases

Configration

DEPRECATED: Mis-spelled class name, alias for Configuration.