Files
codeql/javascript/ql/test/query-tests/Security/CWE-522-DecompressionBombs/unbzip2.js
2025-02-28 13:28:33 +01:00

14 lines
358 B
JavaScript

var bz2 = require('unbzip2-stream');
var fs = require('fs');
const express = require('express')
const fileUpload = require("express-fileupload");
const app = express();
app.use(fileUpload());
app.listen(3000, () => {
});
app.post('/upload', async (req, res) => {
fs.createReadStream(req.query.FilePath).pipe(bz2()).pipe(process.stdout); // $ Alert
});