|
62 | 62 | | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:41 | request.query | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:41 | request.query | user-provided value | |
63 | 63 | | fastify.js:108:28:108:50 | reply.l ... tedCode | fastify.js:94:29:94:51 | request ... plyCode | fastify.js:108:28:108:50 | reply.l ... tedCode | This code execution depends on a $@. | fastify.js:94:29:94:51 | request ... plyCode | user-provided value | |
64 | 64 | | graph-ql.js:20:19:20:22 | expr | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:20:19:20:22 | expr | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value | |
| 65 | +| graph-ql.js:39:19:39:30 | name + title | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:39:19:39:30 | name + title | This code execution depends on a $@. | graph-ql.js:28:32:28:39 | req.body | user-provided value | |
65 | 66 | | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | module.js:9:16:9:29 | req.query.code | This code execution depends on a $@. | module.js:9:16:9:29 | req.query.code | user-provided value | |
66 | 67 | | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | module.js:11:17:11:30 | req.query.code | This code execution depends on a $@. | module.js:11:17:11:30 | req.query.code | user-provided value | |
67 | 68 | | react-native.js:8:32:8:38 | tainted | react-native.js:7:17:7:33 | req.param("code") | react-native.js:8:32:8:38 | tainted | This code execution depends on a $@. | react-native.js:7:17:7:33 | req.param("code") | user-provided value | |
@@ -155,12 +156,23 @@ edges |
155 | 156 | | fastify.js:106:9:106:17 | userInput | fastify.js:107:23:107:31 | userInput | provenance | | |
156 | 157 | | fastify.js:106:21:106:33 | request.query | fastify.js:106:9:106:17 | userInput | provenance | | |
157 | 158 | | fastify.js:106:21:106:38 | request.query.code | fastify.js:106:9:106:17 | userInput | provenance | | |
158 | | -| graph-ql.js:18:12:18:15 | expr | graph-ql.js:18:12:18:15 | expr | provenance | | |
| 159 | +| graph-ql.js:18:10:18:17 | { expr } | graph-ql.js:18:12:18:15 | expr | provenance | | |
159 | 160 | | graph-ql.js:18:12:18:15 | expr | graph-ql.js:20:19:20:22 | expr | provenance | | |
160 | 161 | | graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:11:28:15 | query | provenance | | |
| 162 | +| graph-ql.js:28:9:28:28 | { query, variables } | graph-ql.js:28:18:28:26 | variables | provenance | | |
161 | 163 | | graph-ql.js:28:11:28:15 | query | graph-ql.js:31:13:31:17 | query | provenance | | |
| 164 | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:33:21:33:29 | variables | provenance | | |
| 165 | +| graph-ql.js:28:18:28:26 | variables | graph-ql.js:54:21:54:29 | variables | provenance | | |
162 | 166 | | graph-ql.js:28:32:28:39 | req.body | graph-ql.js:28:9:28:28 | { query, variables } | provenance | | |
163 | | -| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:12:18:15 | expr | provenance | | |
| 167 | +| graph-ql.js:31:13:31:17 | query | graph-ql.js:18:10:18:17 | { expr } | provenance | | |
| 168 | +| graph-ql.js:33:21:33:29 | variables | graph-ql.js:18:10:18:17 | { expr } | provenance | | |
| 169 | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:15:38:18 | name | provenance | | |
| 170 | +| graph-ql.js:38:13:38:27 | { name, title } | graph-ql.js:38:21:38:25 | title | provenance | | |
| 171 | +| graph-ql.js:38:15:38:18 | name | graph-ql.js:39:19:39:22 | name | provenance | | |
| 172 | +| graph-ql.js:38:21:38:25 | title | graph-ql.js:39:26:39:30 | title | provenance | | |
| 173 | +| graph-ql.js:39:19:39:22 | name | graph-ql.js:39:19:39:30 | name + title | provenance | | |
| 174 | +| graph-ql.js:39:26:39:30 | title | graph-ql.js:39:19:39:30 | name + title | provenance | | |
| 175 | +| graph-ql.js:54:21:54:29 | variables | graph-ql.js:38:13:38:27 | { name, title } | provenance | | |
164 | 176 | | react-native.js:7:7:7:13 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | |
165 | 177 | | react-native.js:7:7:7:13 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | |
166 | 178 | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:13 | tainted | provenance | | |
@@ -295,13 +307,22 @@ nodes |
295 | 307 | | fastify.js:106:21:106:38 | request.query.code | semmle.label | request.query.code | |
296 | 308 | | fastify.js:107:23:107:31 | userInput | semmle.label | userInput | |
297 | 309 | | fastify.js:108:28:108:50 | reply.l ... tedCode | semmle.label | reply.l ... tedCode | |
298 | | -| graph-ql.js:18:12:18:15 | expr | semmle.label | expr | |
| 310 | +| graph-ql.js:18:10:18:17 | { expr } | semmle.label | { expr } | |
299 | 311 | | graph-ql.js:18:12:18:15 | expr | semmle.label | expr | |
300 | 312 | | graph-ql.js:20:19:20:22 | expr | semmle.label | expr | |
301 | 313 | | graph-ql.js:28:9:28:28 | { query, variables } | semmle.label | { query, variables } | |
302 | 314 | | graph-ql.js:28:11:28:15 | query | semmle.label | query | |
| 315 | +| graph-ql.js:28:18:28:26 | variables | semmle.label | variables | |
303 | 316 | | graph-ql.js:28:32:28:39 | req.body | semmle.label | req.body | |
304 | 317 | | graph-ql.js:31:13:31:17 | query | semmle.label | query | |
| 318 | +| graph-ql.js:33:21:33:29 | variables | semmle.label | variables | |
| 319 | +| graph-ql.js:38:13:38:27 | { name, title } | semmle.label | { name, title } | |
| 320 | +| graph-ql.js:38:15:38:18 | name | semmle.label | name | |
| 321 | +| graph-ql.js:38:21:38:25 | title | semmle.label | title | |
| 322 | +| graph-ql.js:39:19:39:22 | name | semmle.label | name | |
| 323 | +| graph-ql.js:39:19:39:30 | name + title | semmle.label | name + title | |
| 324 | +| graph-ql.js:39:26:39:30 | title | semmle.label | title | |
| 325 | +| graph-ql.js:54:21:54:29 | variables | semmle.label | variables | |
305 | 326 | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | |
306 | 327 | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | |
307 | 328 | | react-native.js:7:7:7:13 | tainted | semmle.label | tainted | |
|
0 commit comments