Files
codeql/javascript/ql/test/query-tests/Security/CWE-078/tst_shell-command-injection-from-environment.js
Esben Sparre Andreasen ba714a1214 JS: add execa.shell tests
2020-12-22 09:01:43 +01:00

11 lines
383 B
JavaScript

var cp = require('child_process'),
path = require('path'),
execa = require("execa");
(function() {
cp.execFileSync('rm', ['-rf', path.join(__dirname, "temp")]); // GOOD
cp.execSync('rm -rf ' + path.join(__dirname, "temp")); // BAD
execa.shell('rm -rf ' + path.join(__dirname, "temp")); // NOT OK
execa.shellSync('rm -rf ' + path.join(__dirname, "temp")); // NOT OK
});