Files
codeql/javascript/ql/test/query-tests/Security/CWE-078/IndirectCommandInjection/actions.js
2025-02-28 13:29:30 +01:00

15 lines
317 B
JavaScript

import { exec } from "@actions/exec";
import { getInput } from "@actions/core";
exec(process.env['TEST_DATA']); // $ Alert
exec(process.env['GITHUB_ACTION']);
function test(e) {
exec(e['TEST_DATA']); // $ Alert
exec(e['GITHUB_ACTION']);
}
test(process.env); // $ Source
exec(getInput('data')); // $ Alert