Files
codeql/javascript/ql/test/query-tests/Security/CWE-730/tst.js
2025-02-28 13:29:30 +01:00

8 lines
233 B
JavaScript

const express = require('express');
const app = express();
app.get('/foo', (req, res) => {
let data = req.query.data; // $ Source[js/regex-injection]
new RegExp("^"+ data.name + "$", "i"); // $ Alert[js/regex-injection]
});