CodeQL library for JavaScript
Search

Module XmlBombQuery

Provides a taint tracking configuration for reasoning about XML-bomb vulnerabilities.

Note, for performance reasons: only import this file if XmlBomb::Configuration is needed, otherwise XmlBombCustomizations should be imported instead.

Import path

import semmle.javascript.security.dataflow.XmlBombQuery

Imports

XmlBomb
javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Classes

Configuration

A taint-tracking configuration for reasoning about XML-bomb vulnerabilities.