CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.3.1-dev (changelog, source)
Search

Module Xxe

Import path

import semmle.javascript.security.dataflow.XxeCustomizations

Classes

LocationAsSource

An access to document.location, considered as a flow source for XXE vulnerabilities.

RemoteFlowSourceAsSource

DEPRECATED: Use ActiveThreatModelSource from Concepts instead!

Sanitizer

A sanitizer for XXE vulnerabilities.

Sink

A data flow sink for XXE vulnerabilities.

Source

A data flow source for XXE vulnerabilities.

XmlParsingWithExternalEntityResolution

A call to an XML parser that performs external entity expansion, viewed as a data flow sink for XXE vulnerabilities.