var express = require('express'); express().get('/user/', function(req, res) { var evil = req.query.evil; res.send(console.log("
%s
", evil)); // OK (returns undefined) res.send(util.format("
%s
", evil)); // NOT OK res.send(require("printf")("
%s
", evil)); // NOT OK });