CodeQL library for Python
codeql/python-all 4.0.7 (changelog, source)
Search

Module TemplateInjection

Provides default sources, sinks and sanitizers for detecting “template injection” vulnerabilities, as well as extension points for adding your own.

Import path

import semmle.python.security.dataflow.TemplateInjectionCustomizations

Classes

ConstCompareAsSanitizerGuard

A comparison with a constant, considered as a sanitizer-guard.

Sanitizer

A sanitizer for “template injection” vulnerabilities.

Sink

A data flow sink for “template injection” vulnerabilities.

Source

A data flow source for “template injection” vulnerabilities.

TemplateConstructionAsSink

A SQL statement of a SQL construction, considered as a flow sink.