Files
codeql/python/ql/test/experimental/query-tests/Security/CWE-094/Js2PyTest.py
2026-06-15 16:15:17 +01:00

10 lines
227 B
Python

import flask
from js2py import eval_js, disable_pyimport
bp = flask.Blueprint("app", __name__, url_prefix="/")
@bp.route("/bad")
def bad():
jk = flask.request.form["jk"] # $ Source
jk = eval_js(f"{jk} f()") # $ Alert