Sitelet https://web.archive.org/web/20230930063617/https://github.com/github/codeql/pull/14293
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

JS: Dynamic import as code injection sink #14293

Draft
wants to merge 6 commits into
base: main
Choose a base branch
from

Conversation

amammad
Copy link
Contributor

@amammad amammad commented Sep 22, 2023

Dynamic import in nodejs support URLs starts with data: which is dangerous.
There is another nodejs API that accepts the data: URL which is:

const {Worker} = require('node:worker_threads');
new Worker(new URL('data:text/javascript,console.log("hello!");'))

but it needs to be a URL Type as input, not any string value that starts with data:, I'm not sure what is the best way to implement it.

@amammad
Copy link
Contributor Author

amammad commented Sep 28, 2023

Hi, I wanted to add two sinks, one of the sinks should have a new URL instance in one of the middle nodes, so I've used flow steps but it seems that I can't reach some sinks like this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant