Added a step from parse to opts for commander js

This commit is contained in:
Napalys Klicius
2025-08-01 13:12:43 +02:00
parent e980798ede
commit 6b4e34dd39
3 changed files with 21 additions and 2 deletions

View File

@@ -95,6 +95,11 @@ private class ArgsParseStep extends TaintTracking::SharedTaintStep {
pred = call.getArgument(0)
)
or
exists(API::Node commanderNode | commanderNode = commander() |
pred = commanderNode.getMember("parse").getACall().getAnArgument() and
succ = commanderNode.getMember("opts").getACall()
)
or
exists(DataFlow::MethodCallNode methodCall | methodCall = yargs() |
pred = methodCall.getReceiver() and
succ = methodCall