Skip to content

Commit aa9ba95

Browse files
committed
JavaScript: Include 'unzipper' library in ZipSlip.
1 parent 8124980 commit aa9ba95

File tree

1 file changed

+2
-0
lines changed
  • javascript/ql/src/semmle/javascript/security/dataflow

1 file changed

+2
-0
lines changed

javascript/ql/src/semmle/javascript/security/dataflow/ZipSlip.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,8 @@ module ZipSlip {
4545
* Gets a node that can be a parsed archive.
4646
*/
4747
private DataFlow::SourceNode parsedArchive() {
48+
result = DataFlow::moduleImport("unzipper").getAMemberCall("Parse")
49+
or
4850
result = DataFlow::moduleImport("unzip").getAMemberCall("Parse")
4951
or
5052
result = DataFlow::moduleImport("tar-stream").getAMemberCall("extract")

0 commit comments

Comments
 (0)