We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 8124980 commit aa9ba95Copy full SHA for aa9ba95
javascript/ql/src/semmle/javascript/security/dataflow/ZipSlip.qll
@@ -45,6 +45,8 @@ module ZipSlip {
45
* Gets a node that can be a parsed archive.
46
*/
47
private DataFlow::SourceNode parsedArchive() {
48
+ result = DataFlow::moduleImport("unzipper").getAMemberCall("Parse")
49
+ or
50
result = DataFlow::moduleImport("unzip").getAMemberCall("Parse")
51
or
52
result = DataFlow::moduleImport("tar-stream").getAMemberCall("extract")
0 commit comments