mirror of
https://github.com/github/codeql.git
synced 2026-08-06 02:13:10 +02:00
After initial research on our end, we believe that the only vulnerability within the objects() method is passing a query into the __raw__ keyword argument. More info can be found below: http://docs.mongoengine.org/guide/querying.html?highlight=inc__#raw-queries