From 3f43e6ef548eb25e5ef0ce71a78f844b6f09c853 Mon Sep 17 00:00:00 2001 From: jorgectf Date: Tue, 8 Mar 2022 18:45:53 +0100 Subject: [PATCH] Fix `FlaskMail`'s `getTo` --- .../ql/src/experimental/semmle/python/libraries/FlaskMail.qll | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/python/ql/src/experimental/semmle/python/libraries/FlaskMail.qll b/python/ql/src/experimental/semmle/python/libraries/FlaskMail.qll index 58e923faa82..bfe3b943b24 100644 --- a/python/ql/src/experimental/semmle/python/libraries/FlaskMail.qll +++ b/python/ql/src/experimental/semmle/python/libraries/FlaskMail.qll @@ -74,7 +74,7 @@ private module FlaskMail { override DataFlow::Node getTo() { result = this.getFlaskMailArgument(1, "recipients") or - result = flaskMessageInstance().getMember("add_recipient").getACall().getArg(0) + result = this.getMessage().getAMethodCall("add_recipient").getACall().getArg(0) } override DataFlow::Node getFrom() { result = this.getFlaskMailArgument(5, "sender") }