Skip to content
This repository was archived by the owner on Nov 19, 2025. It is now read-only.
This repository was archived by the owner on Nov 19, 2025. It is now read-only.

[Query Create2]: Detect code injection vulnerability in juice-shop/juice-shop app #5

@data-douser

Description

@data-douser

Target Language

javascript

Query Name (Optional)

DemoJsCodeInjection

Query Type

Security

Query Description

https://github.com/github/codeql/blob/main/javascript/ql/src/Security/CWE-094/CodeInjection.inc.qhelp

Expected Severity

Critical

Code Examples

https://github.com/juice-shop/juice-shop/blob/master/routes/showProductReviews.ts

https://github.com/juice-shop/juice-shop/blob/master/lib/utils.ts

CWE/CVE Reference (Optional)

CWE-094

References (Optional)

Expected query test results

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions