Skip to content

Commit 77d4cbc

Browse files
committed
Python: Only allow unsafe positional args to extra
1 parent 3a416bc commit 77d4cbc

File tree

1 file changed

+1
-1
lines changed
  • python/ql/src/experimental/semmle/python/frameworks

1 file changed

+1
-1
lines changed

python/ql/src/experimental/semmle/python/frameworks/Django.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -359,7 +359,7 @@ private module Django {
359359

360360
override DataFlow::Node getSql() {
361361
result.asCfgNode() =
362-
[node.getArg([0 .. 5]), node.getArgByName(["select", "where", "tables", "order_by"])]
362+
[node.getArg([0, 1, 3, 4]), node.getArgByName(["select", "where", "tables", "order_by"])]
363363
}
364364
}
365365
}

0 commit comments

Comments
 (0)