mirror of
https://github.com/github/codeql.git
synced 2026-04-28 18:25:24 +02:00
After initial research on our end, we believe that the only vulnerability within the objects() method is passing a query into the __raw__ keyword argument. More info can be found below: http://docs.mongoengine.org/guide/querying.html?highlight=inc__#raw-queries