diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 287fa61..af7aa51 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -3,5 +3,9 @@ .github/ @PostHog/team-security workflows/ @PostHog/team-security +# semgrep rules and pinned registry snapshots are loaded from main by scan +# workflows org-wide, so changes here alter detection coverage everywhere +.semgrep/ @PostHog/team-security + # we explicitly want this Action to be owned by security, even if the above rules are removed .github/workflows/ci-security.yaml @PostHog/team-security diff --git a/.github/scripts/semgrep_registry.py b/.github/scripts/semgrep_registry.py new file mode 100644 index 0000000..5c633e4 --- /dev/null +++ b/.github/scripts/semgrep_registry.py @@ -0,0 +1,271 @@ +#!/usr/bin/env python3 +"""Vendor Semgrep registry packs as pinned snapshots under .semgrep/registry/. + +Scan workflows point at the snapshot files instead of live `p/...` registry +configs, so a registry-side rule change can never alter CI behavior until a +snapshot update lands on main. The semgrep-registry-update workflow runs +`sync` on a schedule, opens a PR with any changes, and notifies Slack. + +Commands: + sync Fetch every pack in sources.json, rewrite the snapshot + files, and (optionally) write a JSON diff summary. + changed-rules Emit a rules file containing only the added/changed rule + definitions from a `sync` summary, for dry-run scans. + report Render a `sync` summary (plus optional dry-run scan + outputs) as markdown for the update PR body. +""" + +from __future__ import annotations + +import argparse +import io +import json +import sys +import time +import urllib.error +import urllib.request +from pathlib import Path +from typing import Any, Callable + +# ruamel.yaml rather than PyYAML: it is a core dependency of semgrep itself, +# so it is guaranteed inside the semgrep container images this script runs in +# (PyYAML was dropped from the image in 1.172.0). It is also the canonical +# serializer for the snapshots — regenerate them inside the pinned semgrep +# image, not with a locally installed YAML library, to keep output stable. +from ruamel.yaml import YAML + +SEMGREP_URL = "https://semgrep.dev" +FETCH_ATTEMPTS = 3 +FETCH_BACKOFF_SECONDS = 10 +GENERATED_HEADER = ( + "# GENERATED FILE - DO NOT EDIT.\n" + "# Snapshot of Semgrep registry config(s): {sources}\n" + "# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id,\n" + "# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync\n" + "# (the semgrep-registry-update workflow does this on a schedule).\n" +) + + +def _yaml() -> YAML: + parser = YAML(typ="safe", pure=True) + parser.default_flow_style = False + parser.allow_unicode = True + parser.width = 120 + return parser + + +def load_yaml(text: str) -> Any: + return _yaml().load(text) + + +def dump_yaml(data: Any) -> str: + buffer = io.StringIO() + _yaml().dump(data, buffer) + return buffer.getvalue() + + +def fetch_registry_rules(registry_id: str, urlopen: Callable[..., Any] = urllib.request.urlopen) -> list[dict[str, Any]]: + """Download a registry config (p/ or r/) and return its rules.""" + url = f"{SEMGREP_URL}/c/{registry_id}" + request = urllib.request.Request(url, headers={"User-Agent": "posthog-semgrep-registry-sync"}) + last_error: Exception | None = None + for attempt in range(1, FETCH_ATTEMPTS + 1): + try: + with urlopen(request, timeout=120) as response: + raw = response.read().decode("utf-8") + break + except (urllib.error.URLError, TimeoutError, OSError) as error: + last_error = error + if attempt < FETCH_ATTEMPTS: + print(f"Fetch of {url} failed (attempt {attempt}): {error}; retrying", file=sys.stderr) + time.sleep(FETCH_BACKOFF_SECONDS * attempt) + else: + raise RuntimeError(f"Could not fetch {url} after {FETCH_ATTEMPTS} attempts: {last_error}") + + data = load_yaml(raw) + if not isinstance(data, dict) or not isinstance(data.get("rules"), list): + raise RuntimeError(f"Unexpected response from {url}: no top-level 'rules' list") + rules = data["rules"] + for rule in rules: + if not isinstance(rule, dict) or not isinstance(rule.get("id"), str): + raise RuntimeError(f"Unexpected response from {url}: rule without a string 'id'") + return rules + + +def merge_rules(rule_lists: list[list[dict[str, Any]]]) -> dict[str, dict[str, Any]]: + """Merge rule lists into an id-keyed dict, keeping the first definition of duplicate ids.""" + merged: dict[str, dict[str, Any]] = {} + for rules in rule_lists: + for rule in rules: + merged.setdefault(rule["id"], rule) + return merged + + +def render_snapshot(sources: list[str], rules_by_id: dict[str, dict[str, Any]]) -> str: + header = GENERATED_HEADER.format(sources=", ".join(sources)) + body = dump_yaml({"rules": [rules_by_id[rule_id] for rule_id in sorted(rules_by_id)]}) + return header + body + + +def load_snapshot(path: Path) -> dict[str, dict[str, Any]]: + if not path.is_file(): + return {} + data = load_yaml(path.read_text(encoding="utf-8")) + if not isinstance(data, dict) or not isinstance(data.get("rules"), list): + raise RuntimeError(f"Existing snapshot {path} is not a valid rules file") + return {rule["id"]: rule for rule in data["rules"]} + + +def compute_diff(old: dict[str, dict[str, Any]], new: dict[str, dict[str, Any]]) -> dict[str, list[str]]: + return { + "added": sorted(set(new) - set(old)), + "removed": sorted(set(old) - set(new)), + "changed": sorted(rule_id for rule_id in set(old) & set(new) if old[rule_id] != new[rule_id]), + } + + +def load_sources(registry_dir: Path) -> dict[str, list[str]]: + sources_path = registry_dir / "sources.json" + sources = json.loads(sources_path.read_text(encoding="utf-8")) + if not isinstance(sources, dict) or not all( + isinstance(ids, list) and ids and all(isinstance(i, str) for i in ids) for ids in sources.values() + ): + raise RuntimeError(f"{sources_path} must map snapshot names to non-empty lists of registry ids") + return sources + + +def sync(registry_dir: Path, summary_path: Path | None, urlopen: Callable[..., Any] = urllib.request.urlopen) -> dict[str, Any]: + sources = load_sources(registry_dir) + summary: dict[str, Any] = {"snapshots": {}, "totals": {"added": 0, "removed": 0, "changed": 0}} + + for name in sorted(sources): + registry_ids = sources[name] + snapshot_path = registry_dir / f"{name}.yaml" + new_rules = merge_rules([fetch_registry_rules(registry_id, urlopen) for registry_id in registry_ids]) + old_rules = load_snapshot(snapshot_path) + diff = compute_diff(old_rules, new_rules) + snapshot_path.write_text(render_snapshot(registry_ids, new_rules), encoding="utf-8") + + summary["snapshots"][name] = diff + for key in summary["totals"]: + summary["totals"][key] += len(diff[key]) + print( + f"{name}: {len(new_rules)} rules " + f"(+{len(diff['added'])} added, -{len(diff['removed'])} removed, ~{len(diff['changed'])} changed)" + ) + + summary["changed"] = any(summary["totals"].values()) + if summary_path: + summary_path.write_text(json.dumps(summary, indent=2) + "\n", encoding="utf-8") + return summary + + +def changed_rules(registry_dir: Path, summary_path: Path, out_path: Path) -> int: + """Write a rules file with the definitions of every added/changed rule in the summary.""" + summary = json.loads(summary_path.read_text(encoding="utf-8")) + rules: list[dict[str, Any]] = [] + seen: set[str] = set() + for name, diff in sorted(summary["snapshots"].items()): + wanted = set(diff["added"]) | set(diff["changed"]) + if not wanted: + continue + snapshot = load_snapshot(registry_dir / f"{name}.yaml") + for rule_id in sorted(wanted): + if rule_id in seen: + continue + if rule_id not in snapshot: + raise RuntimeError(f"Rule {rule_id} from summary is missing in snapshot {name}.yaml") + rules.append(snapshot[rule_id]) + seen.add(rule_id) + out_path.write_text(dump_yaml({"rules": rules}), encoding="utf-8") + print(f"Wrote {len(rules)} added/changed rule(s) to {out_path}", file=sys.stderr) + print(len(rules)) + return len(rules) + + +def report(summary_path: Path, out_path: Path, dry_run_dir: Path | None) -> None: + """Render the sync summary (and optional per-repo dry-run scan outputs) as markdown.""" + summary = json.loads(summary_path.read_text(encoding="utf-8")) + lines = ["## Semgrep registry snapshot changes", ""] + + totals = summary["totals"] + if not summary.get("changed"): + lines.append("No rule changes.") + else: + lines.append("| Snapshot | Added | Removed | Changed |") + lines.append("| --- | ---: | ---: | ---: |") + for name, diff in sorted(summary["snapshots"].items()): + if any(diff.values()): + lines.append(f"| {name} | {len(diff['added'])} | {len(diff['removed'])} | {len(diff['changed'])} |") + lines.append(f"| **total** | {totals['added']} | {totals['removed']} | {totals['changed']} |") + for kind, label in (("added", "Added"), ("changed", "Changed"), ("removed", "Removed")): + rule_ids = sorted({rule_id for diff in summary["snapshots"].values() for rule_id in diff[kind]}) + if rule_ids: + lines.extend(["", f"### {label} rules", ""]) + lines.extend(f"- `{rule_id}`" for rule_id in rule_ids) + + for dry_run_path in sorted(dry_run_dir.glob("*.json")) if dry_run_dir else []: + # File names encode the scanned repo as owner__repo; owner names + # can't contain underscores, so the first "__" is the separator. + repo = dry_run_path.stem.replace("__", "/", 1) + dry_run = json.loads(dry_run_path.read_text(encoding="utf-8")) + results = dry_run.get("results") or [] + errors = dry_run.get("errors") or [] + lines.extend(["", f"## Dry run of added/changed rules against {repo}", ""]) + lines.append(f"{len(results)} finding(s), {len(errors)} analysis error(s).") + if results: + counts: dict[str, int] = {} + for result in results: + counts[result["check_id"]] = counts.get(result["check_id"], 0) + 1 + lines.extend(["", "| Rule | Findings |", "| --- | ---: |"]) + for rule_id, count in sorted(counts.items(), key=lambda item: (-item[1], item[0])): + lines.append(f"| `{rule_id}` | {count} |") + if errors: + lines.extend(["", "Analysis errors (these would break scans if enforced):", ""]) + seen_messages: set[str] = set() + for error in errors: + message = str(error.get("message", "")).split("\n")[0][:200] + if message not in seen_messages: + lines.append(f"- {message}") + seen_messages.add(message) + + out_path.write_text("\n".join(lines) + "\n", encoding="utf-8") + print(f"Wrote report to {out_path}") + + +def main() -> int: + parser = argparse.ArgumentParser(description=__doc__) + parser.add_argument( + "--registry-dir", + type=Path, + default=Path(__file__).resolve().parents[2] / ".semgrep" / "registry", + help="Directory holding sources.json and the snapshot files", + ) + subparsers = parser.add_subparsers(dest="command", required=True) + + sync_parser = subparsers.add_parser("sync", help="Fetch packs and rewrite snapshots") + sync_parser.add_argument("--summary", type=Path, help="Write a JSON diff summary to this path") + + changed_parser = subparsers.add_parser("changed-rules", help="Emit added/changed rule definitions from a sync summary") + changed_parser.add_argument("--summary", type=Path, required=True) + changed_parser.add_argument("--out", type=Path, required=True) + + report_parser = subparsers.add_parser("report", help="Render a sync summary as markdown") + report_parser.add_argument("--summary", type=Path, required=True) + report_parser.add_argument("--out", type=Path, required=True) + report_parser.add_argument( + "--dry-run-dir", type=Path, help="Directory of per-repo semgrep JSON outputs named owner__repo.json" + ) + + arguments = parser.parse_args() + if arguments.command == "sync": + sync(arguments.registry_dir, arguments.summary) + elif arguments.command == "changed-rules": + changed_rules(arguments.registry_dir, arguments.summary, arguments.out) + else: + report(arguments.summary, arguments.out, arguments.dry_run_dir) + return 0 + + +if __name__ == "__main__": + raise SystemExit(main()) diff --git a/.github/scripts/test_semgrep_registry.py b/.github/scripts/test_semgrep_registry.py new file mode 100644 index 0000000..01684ad --- /dev/null +++ b/.github/scripts/test_semgrep_registry.py @@ -0,0 +1,177 @@ +import io +import json +import tempfile +import unittest +import urllib.error +import urllib.request +from pathlib import Path +from unittest import mock + +import semgrep_registry + + +def rule(rule_id: str, pattern: str = "foo(...)") -> dict: + return {"id": rule_id, "languages": ["python"], "severity": "WARNING", "message": "m", "pattern": pattern} + + +def fake_urlopen(payloads: dict[str, list[dict]]): + def urlopen(request: urllib.request.Request, timeout: int = 0) -> io.BytesIO: + registry_id = request.full_url.split("/c/", 1)[1] + return io.BytesIO(json.dumps({"rules": payloads[registry_id]}).encode("utf-8")) + + return urlopen + + +class FetchRetryTest(unittest.TestCase): + def flaky_urlopen(self, failures: int): + calls = {"count": 0} + + def urlopen(request: urllib.request.Request, timeout: int = 0) -> io.BytesIO: + calls["count"] += 1 + if calls["count"] <= failures: + raise urllib.error.URLError("connection reset") + return io.BytesIO(json.dumps({"rules": [rule("a")]}).encode("utf-8")) + + return urlopen, calls + + def test_fetch_recovers_from_transient_failures(self) -> None: + urlopen, calls = self.flaky_urlopen(failures=semgrep_registry.FETCH_ATTEMPTS - 1) + + with mock.patch.object(semgrep_registry, "FETCH_BACKOFF_SECONDS", 0): + rules = semgrep_registry.fetch_registry_rules("p/test", urlopen) + + self.assertEqual([r["id"] for r in rules], ["a"]) + self.assertEqual(calls["count"], semgrep_registry.FETCH_ATTEMPTS) + + def test_fetch_raises_after_exhausting_attempts(self) -> None: + urlopen, calls = self.flaky_urlopen(failures=semgrep_registry.FETCH_ATTEMPTS) + + with mock.patch.object(semgrep_registry, "FETCH_BACKOFF_SECONDS", 0): + with self.assertRaisesRegex(RuntimeError, "Could not fetch .*p/test"): + semgrep_registry.fetch_registry_rules("p/test", urlopen) + + self.assertEqual(calls["count"], semgrep_registry.FETCH_ATTEMPTS) + + +class DiffTest(unittest.TestCase): + def test_compute_diff(self) -> None: + old = {"a": rule("a"), "b": rule("b"), "c": rule("c")} + new = {"b": rule("b"), "c": rule("c", pattern="bar(...)"), "d": rule("d")} + + self.assertEqual( + semgrep_registry.compute_diff(old, new), + {"added": ["d"], "removed": ["a"], "changed": ["c"]}, + ) + + def test_merge_rules_keeps_first_duplicate(self) -> None: + merged = semgrep_registry.merge_rules([[rule("a", pattern="first")], [rule("a", pattern="second"), rule("b")]]) + + self.assertEqual(sorted(merged), ["a", "b"]) + self.assertEqual(merged["a"]["pattern"], "first") + + def test_snapshot_roundtrip_is_sorted_and_loadable(self) -> None: + rules = {"b": rule("b"), "a": rule("a")} + rendered = semgrep_registry.render_snapshot(["p/test"], rules) + + self.assertTrue(rendered.startswith("# GENERATED FILE")) + self.assertIn("p/test", rendered) + self.assertLess(rendered.index("id: a"), rendered.index("id: b")) + with tempfile.TemporaryDirectory() as directory: + path = Path(directory, "snapshot.yaml") + path.write_text(rendered, encoding="utf-8") + self.assertEqual(semgrep_registry.load_snapshot(path), rules) + + +class SyncTest(unittest.TestCase): + def sync(self, registry_dir: Path, payloads: dict[str, list[dict]]) -> dict: + return semgrep_registry.sync(registry_dir, registry_dir / "summary.json", fake_urlopen(payloads)) + + def test_sync_writes_snapshots_and_diffs(self) -> None: + with tempfile.TemporaryDirectory() as directory: + registry_dir = Path(directory) + (registry_dir / "sources.json").write_text(json.dumps({"test": ["p/one", "p/two"]}), encoding="utf-8") + + first = self.sync(registry_dir, {"p/one": [rule("a")], "p/two": [rule("b")]}) + self.assertTrue(first["changed"]) + self.assertEqual(first["snapshots"]["test"]["added"], ["a", "b"]) + + unchanged = self.sync(registry_dir, {"p/one": [rule("a")], "p/two": [rule("b")]}) + self.assertFalse(unchanged["changed"]) + self.assertEqual(unchanged["totals"], {"added": 0, "removed": 0, "changed": 0}) + + updated = self.sync(registry_dir, {"p/one": [rule("a", pattern="bar(...)")], "p/two": [rule("c")]}) + self.assertTrue(updated["changed"]) + self.assertEqual( + updated["snapshots"]["test"], + {"added": ["c"], "removed": ["b"], "changed": ["a"]}, + ) + self.assertEqual(json.loads((registry_dir / "summary.json").read_text())["totals"]["added"], 1) + + def test_changed_rules_extracts_definitions(self) -> None: + with tempfile.TemporaryDirectory() as directory: + registry_dir = Path(directory) + (registry_dir / "sources.json").write_text(json.dumps({"test": ["p/one"]}), encoding="utf-8") + self.sync(registry_dir, {"p/one": [rule("a"), rule("b")]}) + self.sync(registry_dir, {"p/one": [rule("a"), rule("b", pattern="bar(...)"), rule("c")]}) + + out = registry_dir / "changed.yaml" + count = semgrep_registry.changed_rules(registry_dir, registry_dir / "summary.json", out) + + self.assertEqual(count, 2) + extracted = semgrep_registry.load_snapshot(out) + self.assertEqual(sorted(extracted), ["b", "c"]) + self.assertEqual(extracted["b"]["pattern"], "bar(...)") + + +class ReportTest(unittest.TestCase): + def render(self, summary: dict, dry_runs: dict[str, dict] | None = None) -> str: + with tempfile.TemporaryDirectory() as directory: + summary_path = Path(directory, "summary.json") + summary_path.write_text(json.dumps(summary), encoding="utf-8") + dry_run_dir = None + if dry_runs is not None: + dry_run_dir = Path(directory, "dry-run") + dry_run_dir.mkdir() + for repo, dry_run in dry_runs.items(): + Path(dry_run_dir, repo.replace("/", "__") + ".json").write_text( + json.dumps(dry_run), encoding="utf-8" + ) + out = Path(directory, "report.md") + semgrep_registry.report(summary_path, out, dry_run_dir) + return out.read_text(encoding="utf-8") + + def test_report_lists_rules_and_per_repo_dry_run_counts(self) -> None: + markdown = self.render( + { + "changed": True, + "totals": {"added": 1, "removed": 1, "changed": 0}, + "snapshots": {"test": {"added": ["new.rule"], "removed": ["old.rule"], "changed": []}}, + }, + { + "PostHog/posthog": { + "results": [{"check_id": "new.rule"}, {"check_id": "new.rule"}], + "errors": [{"message": "Internal matching error\ndetails"}], + }, + "PostHog/posthog-js": {"results": [], "errors": []}, + }, + ) + + self.assertIn("| test | 1 | 1 | 0 |", markdown) + self.assertIn("- `new.rule`", markdown) + self.assertIn("- `old.rule`", markdown) + self.assertIn("## Dry run of added/changed rules against PostHog/posthog", markdown) + self.assertIn("2 finding(s), 1 analysis error(s).", markdown) + self.assertIn("| `new.rule` | 2 |", markdown) + self.assertIn("- Internal matching error", markdown) + self.assertIn("## Dry run of added/changed rules against PostHog/posthog-js", markdown) + self.assertIn("0 finding(s), 0 analysis error(s).", markdown) + + def test_report_without_changes_or_dry_run(self) -> None: + markdown = self.render({"changed": False, "totals": {"added": 0, "removed": 0, "changed": 0}, "snapshots": {}}) + + self.assertIn("No rule changes.", markdown) + self.assertNotIn("Dry run", markdown) + + +if __name__ == "__main__": + unittest.main() diff --git a/.github/workflows/ci-security.yml b/.github/workflows/ci-security.yml index af47c86..2108a8c 100644 --- a/.github/workflows/ci-security.yml +++ b/.github/workflows/ci-security.yml @@ -19,21 +19,26 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 container: - image: semgrep/semgrep + image: semgrep/semgrep:1.172.0@sha256:65dcd4408adda7c183a6b4550cb1e9b19f7f627a6fbb7e0559bd466bedc44d7b steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + # Registry packs are pinned as snapshots in .semgrep/registry/ + # (refreshed by the semgrep-registry-update workflow), which is + # also excluded from the scan target — vendored upstream rule + # files aren't ours to lint. # exclude all directories already scanned by other jobs - name: Run Semgrep run: | semgrep \ - --config "p/owasp-top-ten" \ - --config "p/security-audit" \ - --config "p/trailofbits" \ - --config "p/github-actions" \ + --config ".semgrep/registry/owasp-top-ten.yaml" \ + --config ".semgrep/registry/security-audit.yaml" \ + --config ".semgrep/registry/trailofbits.yaml" \ + --config ".semgrep/registry/github-actions.yaml" \ --exclude ".semgrep/rules/*.test.yaml" \ + --exclude ".semgrep/registry" \ --error \ --metrics=off \ --verbose \ diff --git a/.github/workflows/semgrep-package-managers.yml b/.github/workflows/semgrep-package-managers.yml index 5e4bd32..628ca55 100644 --- a/.github/workflows/semgrep-package-managers.yml +++ b/.github/workflows/semgrep-package-managers.yml @@ -20,24 +20,32 @@ jobs: runs-on: ${{ github.event.repository.private && 'depot-ubuntu-latest' || 'ubuntu-latest' }} timeout-minutes: 15 container: - image: semgrep/semgrep:1.163.0@sha256:7cad2bc2d1e44f87f0bf4be6d1fa23aa90fb72015bebc89fb91385d813987a03 + image: semgrep/semgrep:1.172.0@sha256:65dcd4408adda7c183a6b4550cb1e9b19f7f627a6fbb7e0559bd466bedc44d7b steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: fetch-depth: 1 + persist-credentials: false + - name: Checkout .github repo (for pinned registry rule snapshots) + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + repository: PostHog/.github + path: dotgithub-repo + persist-credentials: false + sparse-checkout: | + .semgrep/registry + + # The registry rules are pinned as a snapshot in PostHog/.github + # (.semgrep/registry/, refreshed by the semgrep-registry-update + # workflow) so registry-side rule changes can't break CI here. - name: Run Semgrep run: | semgrep \ - --config "r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age" \ - --config "r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown" \ - --config "r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age" \ - --config "r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate" \ - --config "r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age" \ - --config "r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age" \ - --config "r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown" \ + --config "dotgithub-repo/.semgrep/registry/package-managers.yaml" \ + --exclude "dotgithub-repo" \ --error \ --metrics=off \ --verbose \ diff --git a/.github/workflows/semgrep-registry-update.yml b/.github/workflows/semgrep-registry-update.yml new file mode 100644 index 0000000..606e47d --- /dev/null +++ b/.github/workflows/semgrep-registry-update.yml @@ -0,0 +1,275 @@ +# Keeps the pinned Semgrep registry snapshots in .semgrep/registry/ up to date. +# +# Scan workflows across the org run against those snapshots instead of live +# `p/...` registry configs, so a registry-side rule change can never break CI +# on unrelated PRs. This workflow re-fetches the packs on a schedule; when the +# registry has added/removed/changed rules it: +# 1. dry-runs the added/changed rules against the critical repos listed in +# the SEMGREP_REGISTRY_DRY_RUN_REPOS variable (default PostHog/posthog) +# to measure blast radius (finding counts and analysis errors, without +# failing), +# 2. opens/updates a PR bumping the snapshots (merging the PR is the moment +# the new rules start being enforced org-wide), +# 3. notifies Slack so @team-security can fix occurrences before merging. +# Any job failure also notifies Slack: this is the only path by which the +# org's rules update, so a silent stall would freeze detection coverage. +# +# Required configuration: +# - SEMGREP_REGISTRY_BOT_APP_ID / SEMGREP_REGISTRY_BOT_PRIVATE_KEY secrets for +# a GitHub App with Contents (read & write) and Pull requests (read & write) +# on this repository. +# - SEMGREP_REGISTRY_SLACK_BOT_TOKEN secret and SEMGREP_REGISTRY_SLACK_CHANNEL_ID +# repository variable for the Slack notifications (skipped when unset). +# - SEMGREP_REGISTRY_DRY_RUN_REPOS repository variable: list of repos to +# dry-run against, space- or comma-separated (optional, defaults to +# PostHog/posthog). + +name: Semgrep Registry Update + +on: + schedule: + - cron: '0 6 * * 1-5' + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: semgrep-registry-update + +env: + SEMGREP_ENABLE_VERSION_CHECK: 'false' + +jobs: + detect: + runs-on: ubuntu-latest + timeout-minutes: 45 + container: + image: semgrep/semgrep:1.172.0@sha256:65dcd4408adda7c183a6b4550cb1e9b19f7f627a6fbb7e0559bd466bedc44d7b + outputs: + changed: ${{ steps.sync.outputs.changed }} + steps: + - name: Checkout + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Sync registry snapshots + id: sync + run: | + mkdir -p "$RUNNER_TEMP/artifact" + python3 .github/scripts/semgrep_registry.py sync \ + --summary "$RUNNER_TEMP/artifact/summary.json" + changed=$(python3 -c "import json, os; print(str(json.load(open(os.environ['RUNNER_TEMP'] + '/artifact/summary.json'))['changed']).lower())") + echo "changed=$changed" >> "$GITHUB_OUTPUT" + + - name: Build changed-rules config + id: changed-rules + if: steps.sync.outputs.changed == 'true' + run: | + count=$(python3 .github/scripts/semgrep_registry.py changed-rules \ + --summary "$RUNNER_TEMP/artifact/summary.json" \ + --out "$RUNNER_TEMP/changed-rules.yaml") + echo "count=$count" >> "$GITHUB_OUTPUT" + + # Measures what the added/changed rules would flag today across the + # repos where registry breakage historically hurts most. Never + # fails: the whole point is to see the damage before enforcing + # anything. Scans run from inside each clone so the repo's own + # .semgrepignore applies. + - name: Dry-run added/changed rules against critical repos + if: steps.sync.outputs.changed == 'true' && steps.changed-rules.outputs.count != '0' + env: + DRY_RUN_REPOS: ${{ vars.SEMGREP_REGISTRY_DRY_RUN_REPOS || 'PostHog/posthog' }} + run: | + mkdir -p "$RUNNER_TEMP/artifact/dry-run" + for repo in $(printf '%s' "$DRY_RUN_REPOS" | tr ',' ' '); do + # owner names can't contain underscores, so owner__repo is unambiguous + encoded=$(printf '%s' "$repo" | sed 's|/|__|') + clone_dir="$RUNNER_TEMP/clones/$encoded" + git clone --depth 1 "https://github.com/$repo" "$clone_dir" + ( + cd "$clone_dir" + semgrep \ + --config "$RUNNER_TEMP/changed-rules.yaml" \ + --json-output "$RUNNER_TEMP/artifact/dry-run/$encoded.json" \ + --metrics=off \ + --jobs 4 \ + --timeout 300 \ + . || true + ) + done + + - name: Render report + if: steps.sync.outputs.changed == 'true' + run: | + if [ -d "$RUNNER_TEMP/artifact/dry-run" ]; then + dry_run_args="--dry-run-dir $RUNNER_TEMP/artifact/dry-run" + else + dry_run_args="" + fi + # shellcheck disable=SC2086 # dry_run_args is a controlled flag string + python3 .github/scripts/semgrep_registry.py report \ + --summary "$RUNNER_TEMP/artifact/summary.json" \ + --out "$RUNNER_TEMP/artifact/report.md" \ + $dry_run_args + cp -R .semgrep/registry "$RUNNER_TEMP/artifact/registry" + + - name: Upload update artifact + if: steps.sync.outputs.changed == 'true' + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: registry-update + path: ${{ runner.temp }}/artifact + if-no-files-found: error + + propose: + needs: detect + if: needs.detect.outputs.changed == 'true' + runs-on: ubuntu-latest + timeout-minutes: 15 + env: + SLACK_BOT_TOKEN: ${{ secrets.SEMGREP_REGISTRY_SLACK_BOT_TOKEN }} + BRANCH: semgrep-registry-update + steps: + - name: Generate GitHub App token + id: app-token + uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 + with: + client-id: ${{ secrets.SEMGREP_REGISTRY_BOT_APP_ID }} + private-key: ${{ secrets.SEMGREP_REGISTRY_BOT_PRIVATE_KEY }} + permission-contents: write + permission-pull-requests: write + + # Refreshing the rolling PR replaces its entire content, but stale + # reviews aren't dismissed on push in this repo — so an approval + # would silently transfer to rules nobody looked at, and any commit + # a reviewer added (an --exclude-rule fix, say) would be discarded. + # If the open PR has either, leave it alone and say so in Slack. + - name: Check whether the open snapshot PR is safe to refresh + id: guard + env: + GH_TOKEN: ${{ steps.app-token.outputs.token }} + BOT_LOGIN: ${{ steps.app-token.outputs.app-slug }}[bot] + run: | + # --head matches by branch name alone, which a fork PR can + # spoof to wedge this guard — only same-repo PRs count. + number=$(gh pr list --repo "$GITHUB_REPOSITORY" --head "$BRANCH" --state open --json number,isCrossRepository --jq '[.[] | select(.isCrossRepository == false)][0].number // empty') + if [ -z "$number" ]; then + echo "skip=false" >> "$GITHUB_OUTPUT" + exit 0 + fi + url=$(gh pr view "$number" --repo "$GITHUB_REPOSITORY" --json url --jq .url) + approvals=$(gh pr view "$number" --repo "$GITHUB_REPOSITORY" --json reviews \ + --jq '[.reviews[] | select(.state == "APPROVED")] | length') + foreign=$(gh pr view "$number" --repo "$GITHUB_REPOSITORY" --json commits \ + --jq --arg bot "$BOT_LOGIN" '[.commits[] | select([.authors[].login] | index($bot) | not)] | length') + echo "PR #$number: $approvals approval(s), $foreign non-bot commit(s)" + if [ "$approvals" != "0" ] || [ "$foreign" != "0" ]; then + echo "skip=true" >> "$GITHUB_OUTPUT" + else + echo "skip=false" >> "$GITHUB_OUTPUT" + fi + echo "url=$url" >> "$GITHUB_OUTPUT" + + - name: Checkout + if: steps.guard.outputs.skip != 'true' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + + - name: Download update artifact + if: steps.guard.outputs.skip != 'true' + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: registry-update + path: ${{ runner.temp }}/artifact + + - name: Apply snapshots + if: steps.guard.outputs.skip != 'true' + run: | + rm -rf .semgrep/registry + cp -R "$RUNNER_TEMP/artifact/registry" .semgrep/registry + + # The org requires signed commits on every branch (ruleset + # 20431901), so the commit must be created through GitHub's API — + # sign-commits does that and GitHub signs it server-side. A plain + # `git commit && git push` would be rejected with GH006. The fixed + # branch keeps this to a single rolling PR: reruns replace the + # snapshot commit and refresh the body instead of stacking PRs, + # and identical content results in no push and no notification. + - name: Create or update pull request + id: pr + if: steps.guard.outputs.skip != 'true' + uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 + with: + token: ${{ steps.app-token.outputs.token }} + sign-commits: true + branch: semgrep-registry-update + delete-branch: true + add-paths: .semgrep/registry + commit-message: 'chore(semgrep): update pinned registry rule snapshots' + title: 'chore(semgrep): update pinned registry rule snapshots' + body-path: ${{ runner.temp }}/artifact/report.md + + - name: Build Slack payload + id: slack-payload + if: >- + steps.guard.outputs.skip == 'true' + || steps.pr.outputs['pull-request-operation'] == 'created' + || steps.pr.outputs['pull-request-operation'] == 'updated' + env: + GUARD_SKIP: ${{ steps.guard.outputs.skip }} + GUARD_URL: ${{ steps.guard.outputs.url }} + PR_URL: ${{ steps.pr.outputs['pull-request-url'] }} + SLACK_CHANNEL_ID: ${{ vars.SEMGREP_REGISTRY_SLACK_CHANNEL_ID }} + run: | + if [ "$GUARD_SKIP" = "true" ]; then + text="Semgrep registry changed, but the open snapshot PR has reviews or extra commits, so it was left untouched. Merge or close it to resume refreshes: $GUARD_URL" + jq -n --arg channel "$SLACK_CHANNEL_ID" --arg text "$text" \ + '{channel: $channel, text: $text}' > "$RUNNER_TEMP/slack-payload.json" + else + jq -n \ + --arg channel "$SLACK_CHANNEL_ID" \ + --arg pr_url "$PR_URL" \ + --slurpfile summary "$RUNNER_TEMP/artifact/summary.json" \ + '{ + channel: $channel, + text: ("Semgrep registry changed: " + + ($summary[0].totals.added | tostring) + " added, " + + ($summary[0].totals.changed | tostring) + " changed, " + + ($summary[0].totals.removed | tostring) + " removed rule(s). " + + "These are NOT enforced until the snapshot PR merges: " + $pr_url) + }' > "$RUNNER_TEMP/slack-payload.json" + fi + + - name: Notify Slack + if: steps.slack-payload.outcome == 'success' && env.SLACK_BOT_TOKEN != '' && vars.SEMGREP_REGISTRY_SLACK_CHANNEL_ID != '' + uses: slackapi/slack-github-action@af78098f536edbc4de71162a307590698245be95 # v3.0.1 + with: + method: chat.postMessage + token: ${{ secrets.SEMGREP_REGISTRY_SLACK_BOT_TOKEN }} + payload-file-path: ${{ runner.temp }}/slack-payload.json + + # This workflow is the only path by which the org's Semgrep rules update, + # so a failure must not be silent: it means detection coverage is frozen + # at the last merged snapshot until someone notices. + notify-failure: + needs: [detect, propose] + if: always() && contains(needs.*.result, 'failure') + runs-on: ubuntu-latest + timeout-minutes: 5 + env: + SLACK_BOT_TOKEN: ${{ secrets.SEMGREP_REGISTRY_SLACK_BOT_TOKEN }} + steps: + - name: Notify Slack of failure + if: env.SLACK_BOT_TOKEN != '' && vars.SEMGREP_REGISTRY_SLACK_CHANNEL_ID != '' + uses: slackapi/slack-github-action@af78098f536edbc4de71162a307590698245be95 # v3.0.1 + with: + method: chat.postMessage + token: ${{ secrets.SEMGREP_REGISTRY_SLACK_BOT_TOKEN }} + payload: | + { + "channel": "${{ vars.SEMGREP_REGISTRY_SLACK_CHANNEL_ID }}", + "text": "Semgrep registry update failed — rule snapshots are NOT refreshing until this is fixed: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" + } diff --git a/.github/workflows/semgrep-tests.yml b/.github/workflows/semgrep-tests.yml index 3b843c5..ba2df91 100644 --- a/.github/workflows/semgrep-tests.yml +++ b/.github/workflows/semgrep-tests.yml @@ -15,15 +15,28 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 container: - image: semgrep/semgrep:1.163.0@sha256:7cad2bc2d1e44f87f0bf4be6d1fa23aa90fb72015bebc89fb91385d813987a03 + image: semgrep/semgrep:1.172.0@sha256:65dcd4408adda7c183a6b4550cb1e9b19f7f627a6fbb7e0559bd466bedc44d7b steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + # Scoped to rules/ — .semgrep/registry/ holds vendored registry + # snapshots, which have no test fixtures. - name: Test custom Semgrep rules run: | - semgrep --test .semgrep/ + semgrep --test .semgrep/rules/ + + # Gates snapshot-bump PRs: every vendored pack must at least load + # as a valid rules file, including the ones no workflow in this + # repo scans with (the language packs consumed by PostHog/posthog). + - name: Validate registry snapshots + run: | + for f in .semgrep/registry/*.yaml; do + semgrep --validate --metrics=off --config "$f" + done - name: Test Semgrep result reporting run: | diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index 56b9a4d..3623eb5 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -20,17 +20,26 @@ jobs: runs-on: ${{ github.event.repository.private && 'depot-ubuntu-latest' || 'ubuntu-latest' }} timeout-minutes: 15 container: - image: semgrep/semgrep:1.163.0@sha256:7cad2bc2d1e44f87f0bf4be6d1fa23aa90fb72015bebc89fb91385d813987a03 + image: semgrep/semgrep:1.172.0@sha256:65dcd4408adda7c183a6b4550cb1e9b19f7f627a6fbb7e0559bd466bedc44d7b steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false - name: Checkout .github repo (for custom semgrep rules) uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: repository: PostHog/.github path: dotgithub-repo + persist-credentials: false + # Rules normally resolve from main, but when the repo being + # scanned IS PostHog/.github, use the triggering commit so a + # PR changing rules or registry snapshots is gated by its own + # content — the --strict run below is what catches registry + # rules that fail to parse or analyze before they can merge. + ref: ${{ github.repository == 'PostHog/.github' && github.sha || '' }} sparse-checkout: | .semgrep .github/scripts @@ -51,12 +60,15 @@ jobs: # Local generic-parser replacements preserve their coverage. Remove both exclusions and the # replacements after https://github.com/semgrep/semgrep-rules/issues/3688 is fixed and the # compatibility fixture passes with p/github-actions under --strict. + # Registry packs are pinned as snapshots in PostHog/.github + # (.semgrep/registry/, refreshed by the semgrep-registry-update + # workflow) so registry-side rule changes can't break CI here. semgrep \ --config "dotgithub-repo/.semgrep/rules/" \ - --config "p/owasp-top-ten" \ - --config "p/security-audit" \ - --config "p/trailofbits" \ - --config "p/github-actions" \ + --config "dotgithub-repo/.semgrep/registry/owasp-top-ten.yaml" \ + --config "dotgithub-repo/.semgrep/registry/security-audit.yaml" \ + --config "dotgithub-repo/.semgrep/registry/trailofbits.yaml" \ + --config "dotgithub-repo/.semgrep/registry/github-actions.yaml" \ --exclude-rule trailofbits.generic.curl-unencrypted-url.curl-unencrypted-url \ --exclude-rule dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile \ --exclude-rule trailofbits.generic.redis-unencrypted-transport.redis-unencrypted-transport \ diff --git a/.gitignore b/.gitignore index 2f24661..558c56b 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,4 @@ # Misc .DS_Store -.idea \ No newline at end of file +.idea +__pycache__/ \ No newline at end of file diff --git a/.semgrep/registry/README.md b/.semgrep/registry/README.md new file mode 100644 index 0000000..785c6c1 --- /dev/null +++ b/.semgrep/registry/README.md @@ -0,0 +1,27 @@ +# Pinned Semgrep registry snapshots + +Vendored copies of the Semgrep registry packs used by CI across the org, +fetched anonymously from `https://semgrep.dev/c/`. Scan workflows run +against these files instead of live `p/...` configs so that registry-side +rule changes can never break CI until a snapshot update is reviewed and +merged here. + +- `sources.json` maps each snapshot file to the registry config(s) it pins. +- Every `*.yaml` file is generated — do not edit by hand. Refresh with + `python3 .github/scripts/semgrep_registry.py sync`, run inside the pinned + semgrep container image (which ships the script's ruamel.yaml dependency + and keeps the output byte-stable across environments): + + ```bash + docker run --rm -v "$PWD:/src" -w /src \ + "$(grep -om1 'semgrep/semgrep:[^ ]*' .github/workflows/semgrep-tests.yml)" \ + python3 .github/scripts/semgrep_registry.py sync + ``` + + The `semgrep-registry-update` workflow does this on a schedule and opens a + PR with a diff summary and a dry run against critical repos. + +The rules remain the property of their upstream authors (Semgrep, Trail of +Bits, and other registry contributors) under their respective licenses; each +rule's `metadata` carries its `source` / `license` fields where upstream +provides them. diff --git a/.semgrep/registry/github-actions.yaml b/.semgrep/registry/github-actions.yaml new file mode 100644 index 0000000..b76f8f4 --- /dev/null +++ b/.semgrep/registry/github-actions.yaml @@ -0,0 +1,777 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/github-actions +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + languages: + - yaml + message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this workflow permissions to use the + `set-env` and `add-path` commands. There is a vulnerability in these commands that could result in environment + variables being modified by an attacker. Depending on the use of the environment variable, this could enable an + attacker to, at worst, modify the system path to run a different command than intended, resulting in arbitrary code + execution. This could result in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, use + Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files for more + information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-749: Exposed Dangerous Method or Function' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A06:2017 - Security Misconfiguration + references: + - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ + - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w + - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + semgrep.dev: + rule: + origin: community + r_id: 13412 + rule_id: EwUQ9x + rv_id: 947039 + url: + https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + version_id: jQTzq34 + shortlink: https://sg.run/qq78 + source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Dangerous Method or Function + patterns: + - pattern-either: + - patterns: + - pattern-inside: '{env: ...}' + - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' + severity: WARNING +- id: yaml.github-actions.security.audit.unsafe-add-mask-workflow-command.unsafe-add-mask-workflow-command + languages: + - yaml + message: GitHub Actions provides the **'add-mask'** workflow command to mask sensitive data in the workflow logs. If + **'add-mask'** is not used or if workflow commands have been stopped, sensitive data can leaked into the workflow + logs. An attacker could simply copy the workflow to another branch and add the following payload `echo + "::stop-commands::$stopMarker"` to stop workflow command processing ([described + here](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#stopping-and-starting-workflow-commands)), + which will cause the secret token to be exposed despite the **'add-mask'** usage. For more information, please refer + to the [GitHub documentation](https://github.com/actions/toolkit/blob/main/docs/commands.md#register-a-secret). + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A06:2017 - Security Misconfiguration + references: + - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ + - https://github.com/actions/runner/issues/159 + - https://github.com/actions/runner/issues/475 + - https://github.com/actions/runner/issues/807 + - https://0xn3va.gitbook.io/cheat-sheets/ci-cd/github/actions#misuse-of-sensitive-data-in-workflows + - https://github.com/github/docs/blob/main/content/actions/using-workflows/workflow-commands-for-github-actions.md#masking-a-value-in-a-log + semgrep.dev: + rule: + origin: community + r_id: 138057 + rule_id: GdUvn8y + rv_id: 947040 + url: + https://semgrep.dev/playground/r/1QToZdr/yaml.github-actions.security.audit.unsafe-add-mask-workflow-command.unsafe-add-mask-workflow-command + version_id: 1QToZdr + shortlink: https://sg.run/lBYDo + source: + https://semgrep.dev/r/yaml.github-actions.security.audit.unsafe-add-mask-workflow-command.unsafe-add-mask-workflow-command + subcategory: + - audit + technology: + - github-actions + vulnerability_class: + - Dangerous Method or Function + patterns: + - pattern-regex: '::add-mask::' + severity: WARNING +- id: yaml.github-actions.security.curl-eval.curl-eval + languages: + - yaml + message: Data is being eval'd from a `curl` command. An attacker with control of the server in the `curl` command + could inject malicious code into the `eval`, resulting in a system comrpomise. Avoid eval'ing untrusted data if you + can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its + integrity. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + semgrep.dev: + rule: + origin: community + r_id: 14967 + rule_id: X5Udrd + rv_id: 1263926 + url: https://semgrep.dev/playground/r/YDTZe7K/yaml.github-actions.security.curl-eval.curl-eval + version_id: YDTZe7K + shortlink: https://sg.run/9r7r + source: https://semgrep.dev/r/yaml.github-actions.security.curl-eval.curl-eval + subcategory: + - audit + technology: + - github-actions + - bash + - curl + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern: "$DATA=<... curl ...>\n...\neval <... $DATA ...>\n" + severity: ERROR +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action with the name `discussion.yaml`. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + semgrep.dev: + rule: + origin: community + r_id: 238946 + rule_id: 7KUDRPj + rv_id: 1263927 + url: + https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + version_id: 6xT29ol + shortlink: https://sg.run/JdYPZ + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Command Injection + paths: + include: + - '**/.github/workflows/discussion.yaml' + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: A `run:` step pipes the output of `curl` or `wget` directly into a shell interpreter. This is the "curl | + bash" install pattern — if the remote server is compromised or the URL is hijacked, an attacker can execute + arbitrary code in your CI runner. Consider downloading the file first, verifying its checksum or signature, and then + executing it. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + semgrep.dev: + rule: + origin: community + r_id: 309392 + rule_id: x8UAgrE + rv_id: 1443456 + url: + https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + version_id: 9lT3zYb + shortlink: https://sg.run/GR8K1 + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + subcategory: + - vuln + technology: + - github-actions + - bash + - curl + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + languages: + - yaml + message: 'A secret is exposed in the workflow-level `env:` block, making it available to every job and step in this workflow + — including any untrusted code run in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level + `env:` so the secret is only available where it is actually needed.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets + - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow + semgrep.dev: + rule: + origin: community + r_id: 309393 + rule_id: OrUnq7z + rv_id: 1443457 + url: + https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + version_id: yeTqX9r + shortlink: https://sg.run/Rrn12 + source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + subcategory: + - audit + technology: + - github-actions + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "env:\n ...\n" + - pattern-regex: \$\{\{\s*secrets\. + - pattern-not-inside: 'jobs: ...' + severity: WARNING +- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + languages: + - yaml + message: 'GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by + the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-github-action compromises. Pin + the reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`.' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' + - 'CWE-353: Missing Support for Integrity Check' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions + semgrep.dev: + rule: + origin: community + r_id: 288863 + rule_id: GdUxYDx + rv_id: 1413422 + url: + https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + version_id: xyTRDAd + shortlink: https://sg.run/2LgAL + source: + https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Cryptographic Issues + - Other + patterns: + - pattern-inside: '{steps: ...}' + - pattern: "uses: \"$ACTION\"\n" + - metavariable-pattern: + language: generic + metavariable: $ACTION + patterns: + - pattern-not-regex: ^\./ + - pattern-not-regex: ^docker:// + - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' + severity: WARNING +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: "Using variable interpolation `${{...}}` with `github` context data in a `actions/github-script`'s `script:` step + could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` + context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment + variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: \"$ENVVAR\"." + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + semgrep.dev: + rule: + origin: community + r_id: 31441 + rule_id: OrUQvK + rv_id: 1501843 + url: + https://semgrep.dev/playground/r/e1TboJK/yaml.github-actions.security.github-script-injection.github-script-injection + version_id: e1TboJK + shortlink: https://sg.run/g1G0 + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "uses: $ACTION\n...\n" + - pattern-inside: "with:\n ...\n script: ...\n ...\n" + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `pull_request_target` and checks out code from the incoming pull + request. When using `pull_request_target`, the Action runs in the context of the target repository, which includes + access to all repository secrets. Normally, this is safe because the Action only runs code from the target + repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code + for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to + repository secrets, which would let an attacker steal repository secrets. This normally happens by running build + scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit + your workflow file to make sure no code from the incoming PR is executed. Please see + https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + semgrep.dev: + rule: + origin: community + r_id: 13365 + rule_id: d8Ulkd + rv_id: 1413423 + url: + https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + version_id: O9TQ2nX + shortlink: https://sg.run/jkdn + source: + https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Other + patterns: + - pattern-either: + - pattern-inside: "on:\n ...\n pull_request_target: ...\n ...\n...\n" + - pattern-inside: "on: [..., pull_request_target, ...]\n...\n" + - pattern-inside: "on: pull_request_target\n...\n" + - pattern-inside: "jobs:\n ...\n $JOBNAME:\n ...\n steps:\n ...\n" + - pattern: "...\nuses: \"$ACTION\"\nwith:\n ...\n ref: $EXPR\n" + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern-inside: ${{ ... }} + - pattern-either: + - pattern: github.event.pull_request ... + - pattern: github.head_ref ... + severity: ERROR +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in a `run:` step could allow an attacker to + inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` + to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment + variable, like this: "$ENVVAR".' + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + semgrep.dev: + rule: + origin: community + r_id: 13162 + rule_id: v8UjQj + rv_id: 1501844 + url: + https://semgrep.dev/playground/r/vdTowy6/yaml.github-actions.security.run-shell-injection.run-shell-injection + version_id: vdTowy6 + shortlink: https://sg.run/pkzk + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.secrets-inherit.secrets-inherit + languages: + - yaml + message: "This workflow uses `secrets: inherit` to pass all of the calling workflow's secrets to a reusable workflow. This + violates the principle of least privilege because the called workflow receives access to every secret in the repository, + not just the ones it needs. If the called workflow is compromised or sourced from a third party, an attacker gains access + to all repository secrets. Instead, explicitly pass only the secrets that the called workflow requires using the `secrets:` + map, e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow + - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions + semgrep.dev: + rule: + origin: community + r_id: 288864 + rule_id: ReUQnKg + rv_id: 1413424 + url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit + version_id: e1T42L1 + shortlink: https://sg.run/X2PZB + source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "jobs:\n ...\n" + - pattern: 'secrets: inherit' + severity: ERROR +- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `workflow_run` and checks out code from the incoming pull request. + When using `workflow_run`, the Action runs in the context of the target repository, which includes access to all + repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the + incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the + action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, + which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm + build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to + make sure no code from the incoming PR is executed. Please see + https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A01:2017 - Injection + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability + semgrep.dev: + rule: + origin: community + r_id: 35494 + rule_id: 4bU8E4 + rv_id: 947046 + url: + https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + version_id: kbTYRwl + shortlink: https://sg.run/A0p6 + source: + https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "on:\n ...\n workflow_run: ...\n ...\n...\n" + - pattern-inside: "jobs:\n ...\n $JOBNAME:\n ...\n steps:\n ...\n" + - pattern: "...\nuses: \"$ACTION\"\nwith:\n ...\n ref: $EXPR\n" + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern: ${{ github.event.workflow_run ... }} + severity: WARNING diff --git a/.semgrep/registry/go-lang-security.yaml b/.semgrep/registry/go-lang-security.yaml new file mode 100644 index 0000000..a8e9bb9 --- /dev/null +++ b/.semgrep/registry/go-lang-security.yaml @@ -0,0 +1,2898 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): r/go.lang.security +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + languages: + - go + message: The package `net/http/cgi` is on the import blocklist. The package is vulnerable to httpoxy attacks + (CVE-2015-5386). It is recommended to use `net/http` or a web framework to build a web application instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://godoc.org/golang.org/x/crypto/sha3 + semgrep.dev: + rule: + origin: community + r_id: 9113 + rule_id: yyUnov + rv_id: 1262921 + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + version_id: 2KTv2vJ + shortlink: https://sg.run/l2gj + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import \"net/http/cgi\"\n...\n" + - pattern: "cgi.$FUNC(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + languages: + - go + message: Disabled host key verification detected. This allows man-in-the-middle attacks. Use the + 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. See + https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to learn more about the problem and how to + fix it. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + semgrep.dev: + rule: + origin: community + r_id: 9114 + rule_id: r6UrW9 + rv_id: 1262922 + url: + https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + version_id: X0TzyzN + shortlink: https://sg.run/Yv6X + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Improper Authentication + pattern: ssh.InsecureIgnoreHostKey() + severity: WARNING +- fix: "crypto/rand\n" + id: go.lang.security.audit.crypto.math_random.math-random-used + languages: + - go + message: Do not use `math/rand`. Use `crypto/rand` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + semgrep.dev: + rule: + origin: community + r_id: 9115 + rule_id: bwUwy8 + rv_id: 1262923 + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + version_id: jQTn5nj + shortlink: https://sg.run/6nK6 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "import $RAND \"$MATH\"\n" + - pattern: "import \"$MATH\"\n" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: "...\nrand.$FUNC(...)\n" + - pattern-inside: "...\n$RAND.$FUNC(...)\n" + - focus-metavariable: + - $MATH + severity: WARNING +- fix: "tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }\n" + id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + languages: + - go + message: "`MinVersion` is missing from this TLS configuration. By default, as of Go 1.22, TLS 1.2 is currently used as + the minimum. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where + it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer + 10), it may be necessary to enable TLS 1.0 to provide support. Add `MinVersion: tls.VersionTLS13' to the TLS configuration + to bump the minimum version to TLS 1.3." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9116 + rule_id: NbUk4X + rv_id: 1262924 + url: + https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + version_id: 1QTypyp + shortlink: https://sg.run/oxEN + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "tls.Config{ $...CONF }\n" + - pattern-not: "tls.Config{..., MinVersion: ..., ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + languages: + - go + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151749 + rule_id: GdUvElR + rv_id: 1262925 + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + version_id: 9lT4b4w + shortlink: https://sg.run/ReJwY + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - patterns: + - pattern-inside: "import \"crypto/sha256\"\n...\n" + - pattern-either: + - pattern: "sha256.New224()\n" + - pattern: "sha256.Sum224(...)\n" + - patterns: + - pattern-inside: "import \"golang.org/x/crypto/sha3\"\n...\n" + - pattern-either: + - pattern: "sha3.New224()\n" + - pattern: "sha3.Sum224(...)\n" + severity: WARNING +- fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + languages: + - go + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, SSLv3 will be removed. Instead, + use 'tls.VersionTLS13'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9117 + rule_id: kxUkJ2 + rv_id: 1262926 + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + version_id: yeTxpxj + shortlink: https://sg.run/zvE1 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' + severity: WARNING +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + languages: + - go + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered weak. Use the function + 'tls.CipherSuites()' to get a list of good cipher suites. See + https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other cipher suites to use. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + semgrep.dev: + rule: + origin: community + r_id: 9118 + rule_id: wdUJYk + rv_id: 1262927 + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + version_id: rxTAKAZ + shortlink: https://sg.run/px8N + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + languages: + - go + message: Detected DES cipher algorithm which is insecure. The algorithm is considered weak and has been deprecated. + Use AES instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9121 + rule_id: eqU8B3 + rv_id: 1262930 + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + version_id: kbTzGzA + shortlink: https://sg.run/jREA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/des\"\n...\n" + - pattern-either: + - pattern: "des.NewTripleDESCipher(...)\n" + - pattern: "des.NewCipher(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + languages: + - go + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9119 + rule_id: x8Un6q + rv_id: 1262928 + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + version_id: bZT535Y + shortlink: https://sg.run/2xB5 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/md5\"\n...\n" + - pattern-either: + - pattern: "md5.New()\n" + - pattern: "md5.Sum(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + languages: + - go + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many known vulnerabilities. Use AES + instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9122 + rule_id: v8Unl0 + rv_id: 1262931 + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + version_id: w8TRoRQ + shortlink: https://sg.run/1ZAD + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/rc4\"\n...\n" + - pattern: rc4.NewCipher(...) + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + languages: + - go + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9120 + rule_id: OrU31O + rv_id: 1262929 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + version_id: NdTzyz1 + shortlink: https://sg.run/XBYA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/sha1\"\n...\n" + - pattern-either: + - pattern: "sha1.New()\n" + - pattern: "sha1.Sum(...)\n" + severity: WARNING +- fix: "2048\n" + id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + languages: + - go + message: RSA keys should be at least 2048 bits + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 9123 + rule_id: d8UjY3 + rv_id: 1262932 + url: + https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + version_id: xyTjz8L + shortlink: https://sg.run/9oY4 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "rsa.GenerateKey(..., $BITS)\n" + - pattern: "rsa.GenerateMultiPrimeKey(..., $BITS)\n" + - metavariable-comparison: + comparison: $BITS < 2048 + metavariable: $BITS + - focus-metavariable: + - $BITS + severity: WARNING +- id: go.lang.security.audit.dangerous-command-write.dangerous-command-write + languages: + - go + message: Detected non-static command inside Write. Audit the input to '$CW.Write'. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9107 + rule_id: pKUOZ9 + rv_id: 1262933 + url: + https://semgrep.dev/playground/r/O9Tpx8N/go.lang.security.audit.dangerous-command-write.dangerous-command-write + version_id: O9Tpx8N + shortlink: https://sg.run/Bko5 + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-command-write.dangerous-command-write + subcategory: + - audit + technology: + - go + vulnerability_class: + - Command Injection + patterns: + - pattern: "$CW.Write($BYTE)\n" + - pattern-inside: "$CW,$ERR := $CMD.StdinPipe()\n...\n" + - pattern-not: "$CW.Write(\"...\")\n" + - pattern-not: "$CW.Write([]byte(\"...\"))\n" + - pattern-not: "$CW.Write([]byte(\"...\"+\"...\"))\n" + - pattern-not-inside: "$BYTE = []byte(\"...\");\n...\n" + - pattern-not-inside: "$BYTE = []byte(\"...\"+\"...\");\n...\n" + - pattern-inside: "import \"os/exec\"\n...\n" + severity: ERROR +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + languages: + - go + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9108 + rule_id: 2ZUb8l + rv_id: 1262934 + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + version_id: e1Tyjeg + shortlink: https://sg.run/Dorj + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - patterns: + - pattern: "exec.Cmd {...,Path: $CMD,...}\n" + - pattern-not: "exec.Cmd {...,Path: \"...\",...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: $ARGS,...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{...},...}\n" + - pattern-not-inside: "$ARGS = []string{\"...\",...};\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n$ARGS = []string{$CMD,...};\n...\n" + - pattern-not-inside: "$CMD = exec.LookPath(\"...\");\n...\n$ARGS = []string{$CMD,...};\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,...},...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",...},...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern-either: + - pattern: "exec.Cmd {...,Args: []string{\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$EXE,...},...}\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,\"-c\",$EXE,...},...}\n" + - pattern-inside: "$CMD,$ERR := exec.LookPath(\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\");\n...\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",\"...\",\"...\",...},...}\n" + - pattern-not-inside: "$EXE = \"...\";\n...\n" + - pattern-inside: "import \"os/exec\"\n...\n" + severity: ERROR +- id: go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + languages: + - go + message: Detected non-static command inside Command. Audit the input to 'exec.Command'. If unverified user data can + reach this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to + execute arbitrary code. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9109 + rule_id: X5U8RQ + rv_id: 1262935 + url: + https://semgrep.dev/playground/r/vdT06Xp/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + version_id: vdT06Xp + shortlink: https://sg.run/W8lA + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-command.dangerous-exec-command + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "exec.Command($CMD,...)\n" + - pattern: "exec.CommandContext($CTX,$CMD,...)\n" + - pattern-not: "exec.Command(\"...\",...)\n" + - pattern-not: "exec.CommandContext($CTX,\"...\",...)\n" + - patterns: + - pattern-either: + - pattern: "exec.Command(\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$CMD,...)\n" + - pattern: "exec.CommandContext($CTX,\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$CMD,...)\n" + - pattern-not: "exec.Command(\"...\",\"...\",\"...\",...)\n" + - pattern-not: "exec.CommandContext($CTX,\"...\",\"...\",\"...\",...)\n" + - pattern-either: + - pattern: "exec.Command(\"=~/\\/bin\\/env/\",\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$CMD,...)\n" + - pattern: "exec.CommandContext($CTX,\"=~/\\/bin\\/env/\",\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$CMD,...)\n" + - pattern-inside: "import \"os/exec\"\n...\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + severity: ERROR +- id: go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + languages: + - go + message: Detected non-static command inside Exec. Audit the input to 'syscall.Exec'. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9110 + rule_id: j2UvPl + rv_id: 1262936 + url: + https://semgrep.dev/playground/r/d6Tyx3j/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + version_id: d6Tyx3j + shortlink: https://sg.run/0QRb + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-syscall-exec.dangerous-syscall-exec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - patterns: + - pattern: "syscall.$METHOD($BIN,...)\n" + - pattern-not: "syscall.$METHOD(\"...\",...)\n" + - pattern-not-inside: "$BIN,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$BIN = \"...\";\n...\n" + - patterns: + - pattern: "syscall.$METHOD($BIN,$ARGS,...)\n" + - pattern-not: "syscall.$METHOD($BIN,[]string{\"...\",...},...)\n" + - pattern-not-inside: "$ARGS := []string{\"...\",...};\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n$ARGS = []string{$CMD,...};\n...\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n$ARGS = []string{$CMD,...};\n...\n" + - patterns: + - pattern: "syscall.$METHOD($BIN,[]string{\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$EXE,...},...)\n" + - pattern-not: "syscall.$METHOD($BIN,[]string{\"...\",\"...\",\"...\",...},...)\n" + - patterns: + - pattern: "syscall.$METHOD($BIN,$ARGS,...)\n" + - pattern-either: + - pattern-inside: "$ARGS := []string{\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$EXE,...};\n...\n" + - pattern-inside: "$CMD = \"=~/(sh|bash|ksh|csh|tcsh|zsh)/\";\n...\n$ARGS = []string{$CMD,\"-c\",$EXE,...};\n...\n" + - pattern-inside: "$CMD,$ERR := exec.LookPath(\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\");\n...\n$ARGS = []string{$CMD,\"\ + -c\",$EXE,...};\n...\n" + - pattern-not-inside: "$ARGS := []string{\"...\",\"...\",\"...\",...};\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n$ARGS = []string{$CMD,\"...\",\"...\",...};\n...\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n$ARGS = []string{$CMD,\"...\",\"...\",...};\n...\n" + - pattern-inside: "import \"syscall\"\n...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (Exec|ForkExec) + severity: ERROR +- id: go.lang.security.audit.database.string-formatted-query.string-formatted-query + languages: + - go + message: String-formatted SQL query detected. This could lead to SQL injection if the string is not sanitized + properly. Audit this call to ensure the SQL is not manipulable by external data. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9124 + rule_id: ZqU5bD + rv_id: 1262937 + url: + https://semgrep.dev/playground/r/ZRTKA2q/go.lang.security.audit.database.string-formatted-query.string-formatted-query + version_id: ZRTKA2q + shortlink: https://sg.run/ydEr + source: https://semgrep.dev/r/go.lang.security.audit.database.string-formatted-query.string-formatted-query + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - SQL Injection + patterns: + - metavariable-regex: + metavariable: $OBJ + regex: (?i).*(db|database) + - pattern-not-inside: "$VAR = \"...\" + \"...\"\n...\n$OBJ.$SINK(..., $VAR, ...)\n" + - pattern-not: $OBJ.Exec("...") + - pattern-not: $OBJ.ExecContext($CTX, "...") + - pattern-not: $OBJ.Query("...") + - pattern-not: $OBJ.QueryContext($CTX, "...") + - pattern-not: $OBJ.QueryRow("...") + - pattern-not: $OBJ.QueryRow($CTX, "...") + - pattern-not: $OBJ.QueryRowContext($CTX, "...") + - pattern-either: + - pattern: $OBJ.Exec($X + ...) + - pattern: $OBJ.ExecContext($CTX, $X + ...) + - pattern: $OBJ.Query($X + ...) + - pattern: $OBJ.QueryContext($CTX, $X + ...) + - pattern: $OBJ.QueryRow($X + ...) + - pattern: $OBJ.QueryRow($CTX, $X + ...) + - pattern: $OBJ.QueryRowContext($CTX, $X + ...) + - pattern: $OBJ.Exec(fmt.$P("...", ...)) + - pattern: $OBJ.ExecContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.Query(fmt.$P("...", ...)) + - pattern: $OBJ.QueryContext($CTX, fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow(fmt.$P("...", ...)) + - pattern: $OBJ.QueryRow($CTX, fmt.$U("...", ...)) + - pattern: $OBJ.QueryRowContext($CTX, fmt.$P("...", ...)) + - patterns: + - pattern-either: + - pattern: $QUERY = fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: $QUERY = fmt.Sprintf("$SQLSTR", ...) + - pattern: $QUERY = fmt.Printf("$SQLSTR", ...) + - pattern: $QUERY = $X + ... + - pattern-either: + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.Query($QUERY, ...)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.ExecContext($CTX, $QUERY, ...)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.Exec($QUERY, ...)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.QueryRow($CTX, $QUERY)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.QueryRow($QUERY)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.QueryContext($CTX, $QUERY)\n ...\n}\n" + - pattern-inside: "func $FUNC(...) {\n ...\n $OBJ.QueryRowContext($CTX, $QUERY, ...)\n ...\n}\n" + severity: WARNING +- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - go + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can + use the `golang.org/x/crypto/bcrypt` package. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://pkg.go.dev/golang.org/x/crypto/bcrypt + semgrep.dev: + rule: + origin: community + r_id: 14688 + rule_id: 4bU1Wj + rv_id: 1262938 + url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: nWT2L9r + shortlink: https://sg.run/4eOE + source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5.New + - pattern: md5.Sum + severity: WARNING +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + languages: + - go + message: Detected a network listener listening on 0.0.0.0 or an empty string. This could unexpectedly expose the + server publicly as it binds to all available interfaces. Instead, specify another IP address that is not 0.0.0.0 nor + the empty string. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9125 + rule_id: nJUz3J + rv_id: 1262939 + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + version_id: ExTExoK + shortlink: https://sg.run/rdE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) + severity: WARNING +- fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + languages: + - go + message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs + the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' + flag by setting 'HttpOnly' to 'true' in the Cookie. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9126 + rule_id: EwU2Z6 + rv_id: 1262940 + url: + https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + version_id: 7ZTE3BW + shortlink: https://sg.run/b73e + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n HttpOnly: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + languages: + - go + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the + client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' + to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9127 + rule_id: 7KUQ8X + rv_id: 1262941 + url: + https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + version_id: LjTkgGE + shortlink: https://sg.run/N4G7 + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n Secure: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + languages: + - go + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep could not find a static definition + for '$TRACE'. Dynamic ClientTraces are dangerous because they deserialize function code to run when certain Request + events occur, which could lead to code being run without your knowledge. Ensure that your ClientTrace is statically + defined. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + semgrep.dev: + rule: + origin: community + r_id: 9128 + rule_id: L1Uyjp + rv_id: 1262942 + url: + https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + version_id: 8KT5rNv + shortlink: https://sg.run/kXEK + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-not-inside: "package $PACKAGE\n...\n&httptrace.ClientTrace { ... }\n...\n" + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + languages: + - go + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' does not escape contents. Be + absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may + have a XSS vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + semgrep.dev: + rule: + origin: community + r_id: 9129 + rule_id: 8GUjDW + rv_id: 1262943 + url: + https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + version_id: gETB7Pe + shortlink: https://sg.run/weE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.HTML($OTHER, ...)" + severity: WARNING +- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + languages: + - go + message: "Detected usage of 'http.FileServer' as handler: this allows directory listing and an attacker could navigate through + directories looking for sensitive files. Be sure to disable directory listing or restrict access to specific directories/files." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/OWASP/Go-SCP + - https://cwe.mitre.org/data/definitions/548.html + semgrep.dev: + rule: + origin: community + r_id: 21300 + rule_id: 5rU9JO + rv_id: 1262944 + url: + https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + version_id: QkTGqX0 + shortlink: https://sg.run/4R8x + source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern-inside: "$FS := http.FileServer(...)\n...\n" + - pattern-either: + - pattern: "http.ListenAndServe(..., $FS)\n" + - pattern: "http.ListenAndServeTLS(..., $FS)\n" + - pattern: "http.Handle(..., $FS)\n" + - pattern: "http.HandleFunc(..., $FS)\n" + - patterns: + - pattern: "http.$FN(..., http.FileServer(...))\n" + - metavariable-regex: + metavariable: $FN + regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc) + severity: WARNING +- id: go.lang.security.audit.net.pprof.pprof-debug-exposure + languages: + - go + message: The profiling 'pprof' endpoint is automatically exposed on /debug/pprof. This could leak information about + the server. Instead, use `import "net/http/pprof"`. See + https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ for more information and mitigation. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-489: Active Debug Code' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A06:2017 - Security Misconfiguration + references: + - https://www.farsightsecurity.com/blog/txt-record/go-remote-profiling-20161028/ + semgrep.dev: + rule: + origin: community + r_id: 9130 + rule_id: gxU1Kp + rv_id: 945583 + url: https://semgrep.dev/playground/r/9lTy168/go.lang.security.audit.net.pprof.pprof-debug-exposure + version_id: 9lTy168 + shortlink: https://sg.run/x1Ep + source: https://semgrep.dev/r/go.lang.security.audit.net.pprof.pprof-debug-exposure + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - audit + technology: + - go + vulnerability_class: + - Active Debug Code + patterns: + - pattern-inside: "import _ \"net/http/pprof\"\n...\n" + - pattern-inside: "func $ANY(...) {\n ...\n}\n" + - pattern-not-inside: "$MUX = http.NewServeMux(...)\n...\nhttp.ListenAndServe($ADDR, $MUX)\n" + - pattern-not: http.ListenAndServe("=~/^localhost.*/", ...) + - pattern-not: http.ListenAndServe("=~/^127[.]0[.]0[.]1.*/", ...) + - pattern: http.ListenAndServe(...) + severity: WARNING +- id: go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + languages: + - go + message: Found a formatted template string passed to 'template. HTMLAttr()'. 'template.HTMLAttr()' does not escape + contents. Be absolutely sure there is no user-controlled data in this template or validate and sanitize the data + before passing it into the template. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTMLAttr + semgrep.dev: + rule: + origin: community + r_id: 9131 + rule_id: QrUz9R + rv_id: 1262945 + url: + https://semgrep.dev/playground/r/3ZT4XRr/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + version_id: 3ZT4XRr + shortlink: https://sg.run/OPRp + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-htmlattr.unescaped-data-in-htmlattr + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + pattern-either: + - pattern: template.HTMLAttr($T + $X, ...) + - pattern: template.HTMLAttr(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.HTMLAttr($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.HTMLAttr($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.HTMLAttr($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.HTMLAttr($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.HTMLAttr($OTHER, ...)" + severity: WARNING +- id: go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + languages: + - go + message: Found a formatted template string passed to 'template.JS()'. 'template.JS()' does not escape contents. Be + absolutely sure there is no user-controlled data in this template. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#JS + semgrep.dev: + rule: + origin: community + r_id: 9132 + rule_id: 3qUP8K + rv_id: 1262946 + url: + https://semgrep.dev/playground/r/44TEj9E/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + version_id: 44TEj9E + shortlink: https://sg.run/eLNl + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-js.unescaped-data-in-js + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + pattern-either: + - pattern: template.JS($T + $X, ...) + - pattern: template.JS(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.JS($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.JS($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.JS($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.JS($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.JS($OTHER, ...)\n" + severity: WARNING +- id: go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + languages: + - go + message: Found a formatted template string passed to 'template.URL()'. 'template.URL()' does not escape contents, and + this could result in XSS (cross-site scripting) and therefore confidential data being stolen. Sanitize data coming + into this function or make sure that no user-controlled input is coming into the function. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#URL + semgrep.dev: + rule: + origin: community + r_id: 9133 + rule_id: 4bUkDW + rv_id: 1262947 + url: + https://semgrep.dev/playground/r/PkTR3zz/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + version_id: PkTR3zz + shortlink: https://sg.run/vzE4 + source: https://semgrep.dev/r/go.lang.security.audit.net.unescaped-data-in-url.unescaped-data-in-url + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + pattern-either: + - pattern: template.URL($T + $X, ...) + - pattern: template.URL(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.URL($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.URL($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.URL($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.URL($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.URL($OTHER, ...)" + severity: WARNING +- fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + id: go.lang.security.audit.net.use-tls.use-tls + languages: + - go + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See + https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + semgrep.dev: + rule: + origin: community + r_id: 9134 + rule_id: PeUZ8X + rv_id: 1262948 + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + version_id: JdTzxkn + shortlink: https://sg.run/dKbY + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern: http.ListenAndServe($ADDR, $HANDLER) + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + languages: + - go + message: Found data going from url query parameters into formatted data written to ResponseWriter. This could be XSS + and should not be done. If you must do this, ensure your data is sanitized or escaped. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9135 + rule_id: JDUyXB + rv_id: 1262949 + url: + https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + version_id: 5PTo1qr + shortlink: https://sg.run/Zvon + source: + https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "func $FUNC(..., $W http.ResponseWriter, ...) {\n ...\n var $TEMPLATE = \"...\"\n ...\n $W.Write([]byte(fmt.$PRINTF($TEMPLATE, + ...)), ...)\n ...\n}\n" + - pattern-either: + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n\ + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $INTERM, + ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $DATA, ...)))\n" + severity: WARNING +- id: go.lang.security.audit.reflect-makefunc.reflect-makefunc + languages: + - go + message: "'reflect.MakeFunc' detected. This will sidestep protections that are normally afforded by Go's type system. Audit + this call and be sure that user input cannot be used to affect the code generated by MakeFunc; otherwise, you will have + a serious security vulnerability." + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9111 + rule_id: 10UKGb + rv_id: 1262950 + url: https://semgrep.dev/playground/r/GxTkeqB/go.lang.security.audit.reflect-makefunc.reflect-makefunc + version_id: GxTkeqB + shortlink: https://sg.run/KlPd + source: https://semgrep.dev/r/go.lang.security.audit.reflect-makefunc.reflect-makefunc + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + pattern: reflect.MakeFunc(...) + severity: ERROR +- id: go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + languages: + - go + message: Detected string concatenation with a non-literal variable in a "database/sql" Go SQL statement. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL + injection, use parameterized queries or prepared statements instead. You can use prepared statements with the + 'Prepare' and 'PrepareContext' calls. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/database/sql/ + semgrep.dev: + rule: + origin: community + r_id: 10258 + rule_id: YGUrnQ + rv_id: 1262951 + url: https://semgrep.dev/playground/r/RGT0Lpr/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + version_id: RGT0Lpr + shortlink: https://sg.run/YgOX + source: https://semgrep.dev/r/go.lang.security.audit.sqli.gosql-sqli.gosql-sqli + subcategory: + - vuln + technology: + - go + vulnerability_class: + - SQL Injection + patterns: + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: "$QUERY = $X + $Y\n...\n" + - pattern-inside: "$QUERY += $X\n...\n" + - pattern-inside: "$QUERY = fmt.Sprintf(\"...\", $PARAM1, ...)\n...\n" + - pattern-not-inside: "$QUERY += \"...\"\n...\n" + - pattern-not-inside: "$QUERY = \"...\" + \"...\"\n...\n" + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: "$DB, ... = sql.Open(...)\n...\n" + - pattern-inside: "func $FUNCNAME(..., $DB *sql.DB, ...) {\n ...\n}\n" + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecContent|Query|QueryContext|QueryRow|QueryRowContext)$ + severity: ERROR +- id: go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + languages: + - go + message: Detected string concatenation with a non-literal variable in a go-pg ORM SQL statement. This could lead to + SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, do + not use strings concatenated with user-controlled input. Instead, use parameterized statements. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pg.uptrace.dev/queries/ + semgrep.dev: + rule: + origin: community + r_id: 10259 + rule_id: 6JUqQ1 + rv_id: 1262952 + url: https://semgrep.dev/playground/r/A8Tgdqn/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + version_id: A8Tgdqn + shortlink: https://sg.run/6rA6 + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-orm-sqli.pg-orm-sqli + subcategory: + - vuln + technology: + - go-pg + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "import (\n ...\n \"$IMPORT\"\n)\n...\n" + - metavariable-regex: + metavariable: $IMPORT + regex: .*go-pg + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: "$QUERY = $X + $Y\n...\n" + - pattern-inside: "$QUERY += $X\n...\n" + - pattern-inside: "$QUERY = fmt.Sprintf(\"...\", $PARAM1, ...)\n...\n" + - pattern-not-inside: "$QUERY += \"...\"\n...\n" + - pattern-not-inside: "$QUERY = \"...\" + \"...\"\n...\n" + - pattern: "$DB.$INTFUNC1(...).$METHOD(..., $X + $Y, ...).$INTFUNC2(...)\n" + - pattern: "$DB.$METHOD(..., fmt.Sprintf(\"...\", $PARAM1, ...), ...)\n" + - pattern-inside: "$DB = pg.Connect(...)\n...\n" + - pattern-inside: "func $FUNCNAME(..., $DB *pg.DB, ...) {\n ...\n}\n" + - pattern-not-inside: "$QUERY = fmt.Sprintf(\"...\", ...,\"...\", ...)\n...\n" + - pattern-not-inside: "$QUERY += \"...\"\n...\n" + - pattern-not: $DB.$METHOD(...,"...",...) + - pattern-not: "$DB.$INTFUNC1(...).$METHOD(..., \"...\", ...).$INTFUNC2(...)\n" + - pattern-not-inside: "$QUERY = \"...\" + \"...\"\n" + - pattern-not: "\"...\"\n" + - pattern-not: path.Join(...) + - pattern-not: filepath.Join(...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Where|WhereOr|Join|GroupExpr|OrderExpr|ColumnExpr)$ + severity: ERROR +- id: go.lang.security.audit.sqli.pg-sqli.pg-sqli + languages: + - go + message: "Detected string concatenation with a non-literal variable in a go-pg SQL statement. This could lead to SQL injection + if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries + instead of string concatenation. You can use parameterized queries like so: '(SELECT ? FROM table, data1)'" + metadata: + category: security + confidence: LOW + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pg.uptrace.dev/ + - https://pkg.go.dev/github.com/go-pg/pg/v10 + semgrep.dev: + rule: + origin: community + r_id: 10294 + rule_id: AbUWXY + rv_id: 1262953 + url: https://semgrep.dev/playground/r/BjTkZbQ/go.lang.security.audit.sqli.pg-sqli.pg-sqli + version_id: BjTkZbQ + shortlink: https://sg.run/Al94 + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pg-sqli.pg-sqli + subcategory: + - vuln + technology: + - go-pg + vulnerability_class: + - SQL Injection + patterns: + - pattern-either: + - patterns: + - pattern: "$DB.$METHOD(...,$QUERY,...)\n" + - pattern-either: + - pattern-inside: "$QUERY = $X + $Y\n...\n" + - pattern-inside: "$QUERY += $X\n...\n" + - pattern-inside: "$QUERY = fmt.Sprintf(\"...\", $PARAM1, ...)\n...\n" + - pattern-not-inside: "$QUERY += \"...\"\n...\n" + - pattern-not-inside: "$QUERY = \"...\" + \"...\"\n...\n" + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: "$DB = pg.Connect(...)\n...\n" + - pattern-inside: "func $FUNCNAME(..., $DB *pg.DB, ...) {\n ...\n}\n" + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecContext|ExecOne|ExecOneContext|Query|QueryOne|QueryContext|QueryOneContext)$ + severity: ERROR +- id: go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + languages: + - go + message: 'Detected string concatenation with a non-literal variable in a pgx Go SQL statement. This could lead to SQL injection + if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries + instead. You can use parameterized queries like so: (`SELECT $1 FROM table`, `data1)' + metadata: + category: security + confidence: LOW + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/jackc/pgx + - https://pkg.go.dev/github.com/jackc/pgx/v4#hdr-Connection_Pool + semgrep.dev: + rule: + origin: community + r_id: 10260 + rule_id: oqUz92 + rv_id: 1262954 + url: https://semgrep.dev/playground/r/DkTRbkL/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + version_id: DkTRbkL + shortlink: https://sg.run/okKN + source: https://semgrep.dev/r/go.lang.security.audit.sqli.pgx-sqli.pgx-sqli + subcategory: + - vuln + technology: + - pgx + vulnerability_class: + - SQL Injection + patterns: + - pattern-either: + - patterns: + - pattern: $DB.$METHOD(...,$QUERY,...) + - pattern-either: + - pattern-inside: "$QUERY = $X + $Y\n...\n" + - pattern-inside: "$QUERY += $X\n...\n" + - pattern-inside: "$QUERY = fmt.Sprintf(\"...\", $PARAM1, ...)\n...\n" + - pattern-not-inside: "$QUERY += \"...\"\n...\n" + - pattern-not-inside: "$QUERY = \"...\" + \"...\"\n...\n" + - pattern: $DB.$METHOD(..., $X + $Y, ...) + - pattern: $DB.$METHOD(..., fmt.Sprintf("...", $PARAM1, ...), ...) + - pattern-either: + - pattern-inside: "$DB, ... = pgx.Connect(...)\n...\n" + - pattern-inside: "$DB, ... = pgx.NewConnPool(...)\n...\n" + - pattern-inside: "$DB, ... = pgx.ConnectConfig(...)\n...\n" + - pattern-inside: "func $FUNCNAME(..., $DB *pgx.Conn, ...) {\n ...\n}\n" + - pattern-not: $DB.$METHOD(..., "..." + "...", ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Exec|ExecEx|Query|QueryEx|QueryRow|QueryRowEx)$ + severity: ERROR +- id: go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + languages: + - go + message: If an attacker can supply values that the application then uses to determine which method or field to invoke, + the potential exists for the attacker to create control flow paths through the application that were not intended by + the application developers. This attack vector may allow the attacker to bypass authentication or access control + checks or otherwise cause the application to behave in an unexpected manner. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 10005 + rule_id: BYUBdJ + rv_id: 1262955 + url: + https://semgrep.dev/playground/r/WrTqK8e/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + version_id: WrTqK8e + shortlink: https://sg.run/R8Xv + source: https://semgrep.dev/r/go.lang.security.audit.unsafe-reflect-by-name.unsafe-reflect-by-name + subcategory: + - audit + technology: + - go + vulnerability_class: + - Improper Authorization + patterns: + - pattern-either: + - pattern: "$SMTH.MethodByName($NAME,...)\n" + - pattern: "$SMTH.FieldByName($NAME,...)\n" + - pattern-not: "$SMTH.MethodByName(\"...\",...)\n" + - pattern-not: "$SMTH.FieldByName(\"...\",...)\n" + - pattern-inside: "import \"reflect\"\n...\n" + severity: WARNING +- id: go.lang.security.audit.unsafe.use-of-unsafe-block + languages: + - go + message: Using the unsafe package in Go gives you low-level memory management and many of the strengths of the C + language, but also steps around the type safety of Go and can lead to buffer overflows and possible arbitrary code + execution by an attacker. Only use this package if you absolutely know what you're doing. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-242: Use of Inherently Dangerous Function' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://cwe.mitre.org/data/definitions/242.html + semgrep.dev: + rule: + origin: community + r_id: 9112 + rule_id: 9AU1p1 + rv_id: 945595 + url: https://semgrep.dev/playground/r/ZRT35Wd/go.lang.security.audit.unsafe.use-of-unsafe-block + version_id: ZRT35Wd + shortlink: https://sg.run/qxEx + source: https://semgrep.dev/r/go.lang.security.audit.unsafe.use-of-unsafe-block + source_rule_url: https://github.com/securego/gosec/blob/master/rules/unsafe.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Dangerous Method or Function + pattern: unsafe.$FUNC(...) + severity: WARNING +- fix: "html/template\n" + id: go.lang.security.audit.xss.import-text-template.import-text-template + languages: + - go + message: When working with web applications that involve rendering user-generated content, it's important to properly + escape any HTML content to prevent Cross-Site Scripting (XSS) attacks. In Go, the `text/template` package does not + automatically escape HTML content, which can leave your application vulnerable to these types of attacks. To + mitigate this risk, it's recommended to use the `html/template` package instead, which provides built-in + functionality for HTML escaping. By using `html/template` to render your HTML content, you can help to ensure that + your web application is more secure and less susceptible to XSS vulnerabilities. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.veracode.com/blog/secure-development/use-golang-these-mistakes-could-compromise-your-apps-security + semgrep.dev: + rule: + origin: community + r_id: 9136 + rule_id: 5rUOZQ + rv_id: 1262956 + url: + https://semgrep.dev/playground/r/0bTKzok/go.lang.security.audit.xss.import-text-template.import-text-template + version_id: 0bTKzok + shortlink: https://sg.run/ndEO + source: https://semgrep.dev/r/go.lang.security.audit.xss.import-text-template.import-text-template + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern: "import \"$IMPORT\"\n" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(text/template)$ + - focus-metavariable: $IMPORT + severity: WARNING +- id: go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + languages: + - go + message: Detected directly writing or similar in 'http.ResponseWriter.write()'. This bypasses HTML escaping that + prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package and render data using + 'template.Execute()'. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 9137 + rule_id: GdU71y + rv_id: 1262957 + url: + https://semgrep.dev/playground/r/K3TKkoB/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + version_id: K3TKkoB + shortlink: https://sg.run/EkbA + source: + https://semgrep.dev/r/go.lang.security.audit.xss.no-direct-write-to-responsewriter.no-direct-write-to-responsewriter + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-either: + - pattern-inside: "func $HANDLER(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-inside: "func $HANDLER(..., $WRITER *http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-inside: "func(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-either: + - pattern: $WRITER.Write(...) + - pattern: (*$WRITER).Write(...) + - pattern-not: $WRITER.Write([]byte("...")) + severity: WARNING +- id: go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + languages: + - go + message: Detected 'Fprintf' or similar writing to 'http.ResponseWriter'. This bypasses HTML escaping that prevents + cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 9138 + rule_id: ReUgyJ + rv_id: 1262958 + url: + https://semgrep.dev/playground/r/qkTR7OP/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + version_id: qkTR7OP + shortlink: https://sg.run/7oqR + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-fprintf-to-responsewriter.no-fprintf-to-responsewriter + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-either: + - pattern-inside: "func $HANDLER(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-inside: "func(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-not: fmt.$PRINTF($WRITER, "...") + - pattern: fmt.$PRINTF($WRITER, ...) + severity: WARNING +- id: go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + languages: + - generic + message: Detected template variable interpolation in an HTML tag. This is potentially vulnerable to cross-site + scripting (XSS) attacks because a malicious actor has control over HTML but without the need to use escaped + characters. Use explicit tags instead. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/golang/go/issues/19669 + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 9139 + rule_id: AbUzBB + rv_id: 1262959 + url: + https://semgrep.dev/playground/r/l4TJRZK/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + version_id: l4TJRZK + shortlink: https://sg.run/LwJJ + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-in-tag.no-interpolation-in-tag + subcategory: + - audit + technology: + - generic + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.html' + - '*.thtml' + - '*.gohtml' + - '*.tmpl' + - '*.tpl' + pattern: <{{ ... }} ... > + severity: WARNING +- id: go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + languages: + - generic + message: Detected template variable interpolation in a JavaScript template string. This is potentially vulnerable to + cross-site scripting (XSS) attacks because a malicious actor has control over JavaScript but without the need to use + escaped characters. Instead, obtain this variable outside of the template string and ensure your template is + properly escaped. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/golang/go/issues/9200#issuecomment-66100328 + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 9140 + rule_id: BYUNR6 + rv_id: 1262960 + url: + https://semgrep.dev/playground/r/YDTZeEB/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + version_id: YDTZeEB + shortlink: https://sg.run/8yl7 + source: + https://semgrep.dev/r/go.lang.security.audit.xss.no-interpolation-js-template-string.no-interpolation-js-template-string + subcategory: + - audit + technology: + - generic + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.html' + - '*.thtml' + - '*.gohtml' + - '*.tmpl' + - '*.tpl' + patterns: + - pattern-inside: + - pattern: '` ... {{ ... }} ...`' + severity: WARNING +- id: go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + languages: + - go + message: Detected 'io.WriteString()' writing directly to 'http.ResponseWriter'. This bypasses HTML escaping that + prevents cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + - https://golang.org/pkg/io/#WriteString + semgrep.dev: + rule: + origin: community + r_id: 9141 + rule_id: DbUpEr + rv_id: 1262961 + url: + https://semgrep.dev/playground/r/6xT2983/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + version_id: 6xT2983 + shortlink: https://sg.run/gLwn + source: + https://semgrep.dev/r/go.lang.security.audit.xss.no-io-writestring-to-responsewriter.no-io-writestring-to-responsewriter + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-either: + - pattern-inside: "func $HANDLER(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-inside: "func(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-not: io.WriteString($WRITER, "...") + - pattern: io.WriteString($WRITER, $STRING) + severity: WARNING +- id: go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + languages: + - go + message: Detected 'printf' or similar in 'http.ResponseWriter.write()'. This bypasses HTML escaping that prevents + cross-site scripting vulnerabilities. Instead, use the 'html/template' package to render data to users. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 9142 + rule_id: WAUoLp + rv_id: 1262962 + url: + https://semgrep.dev/playground/r/o5TbDdq/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + version_id: o5TbDdq + shortlink: https://sg.run/Q5BP + source: https://semgrep.dev/r/go.lang.security.audit.xss.no-printf-in-responsewriter.no-printf-in-responsewriter + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-either: + - pattern-inside: "func $HANDLER(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern-inside: "func(..., $WRITER http.ResponseWriter, ...) {\n ...\n}\n" + - pattern: "$WRITER.Write(<... fmt.$PRINTF(...) ...>, ...)\n" + severity: WARNING +- id: go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + languages: + - go + message: Semgrep could not determine that the argument to 'template.HTML()' is a constant. 'template.HTML()' and + similar does not escape contents. Be absolutely sure there is no user-controlled data in this template. If user data + can reach this template, you may have a XSS vulnerability. Instead, do not use this function and use + 'template.Execute()'. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/vulnerability/xss/xss.go#L33 + semgrep.dev: + rule: + origin: community + r_id: 9143 + rule_id: 0oU5n3 + rv_id: 1262963 + url: + https://semgrep.dev/playground/r/zyTb2Lz/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + version_id: zyTb2Lz + shortlink: https://sg.run/3xDb + source: https://semgrep.dev/r/go.lang.security.audit.xss.template-html-does-not-escape.unsafe-template-type + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-not: template.$ANY("..." + "...") + - pattern-not: template.$ANY("...") + - pattern-either: + - pattern: template.HTML(...) + - pattern: template.CSS(...) + - pattern: template.HTMLAttr(...) + - pattern: template.JS(...) + - pattern: template.JSStr(...) + - pattern: template.Srcset(...) + - pattern: template.URL(...) + severity: WARNING +- id: go.lang.security.audit.xxe.parsing-external-entities-enabled.parsing-external-entities-enabled + languages: + - go + message: Detected enabling of "XMLParseNoEnt", which allows parsing of external entities and can lead to XXE if user + controlled data is parsed by the library. Instead, do not enable "XMLParseNoEnt" or be sure to adequately sanitize + user-controlled data when it is being parsed by this library. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://knowledge-base.secureflag.com/vulnerabilities/xml_injection/xml_entity_expansion_go_lang.html + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + semgrep.dev: + rule: + origin: community + r_id: 18794 + rule_id: WAUdLP + rv_id: 1262964 + url: + https://semgrep.dev/playground/r/pZT03n5/go.lang.security.audit.xxe.parsing-external-entities-enabled.parsing-external-entities-enabled + version_id: pZT03n5 + shortlink: https://sg.run/A51w + source: + https://semgrep.dev/r/go.lang.security.audit.xxe.parsing-external-entities-enabled.parsing-external-entities-enabled + subcategory: + - audit + technology: + - libxml2 + vulnerability_class: + - XML Injection + patterns: + - pattern-inside: "import (\"github.com/lestrrat-go/libxml2/parser\")\n...\n" + - pattern: $PARSER := parser.New(parser.XMLParseNoEnt) + severity: WARNING +- id: go.lang.security.bad_tmp.bad-tmp-file-creation + languages: + - go + message: File creation in shared tmp directory without using `io.CreateTemp`. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-377: Insecure Temporary File' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://pkg.go.dev/io/ioutil#TempFile + - https://pkg.go.dev/os#CreateTemp + - https://github.com/securego/gosec/blob/5fd2a370447223541cddb35da8d1bc707b7bb153/rules/tempfiles.go#L67 + semgrep.dev: + rule: + origin: community + r_id: 9104 + rule_id: 6JUjnL + rv_id: 1262965 + url: https://semgrep.dev/playground/r/2KTv2pJ/go.lang.security.bad_tmp.bad-tmp-file-creation + version_id: 2KTv2pJ + shortlink: https://sg.run/Gejn + source: https://semgrep.dev/r/go.lang.security.bad_tmp.bad-tmp-file-creation + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Other + pattern-either: + - pattern: ioutil.WriteFile("=~//tmp/.*$/", ...) + - pattern: os.Create("=~//tmp/.*$/", ...) + - pattern: os.WriteFile("=~//tmp/.*$/", ...) + severity: WARNING +- fix-regex: + regex: (.*)(Copy|CopyBuffer)\((.*?),(.*?)(\)|,.*\)) + replacement: \1CopyN(\3, \4, 1024*1024*256) + id: go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + languages: + - go + message: 'Detected a possible denial-of-service via a zip bomb attack. By limiting the max bytes read, you can mitigate + this attack. `io.CopyN()` can specify a size. ' + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-400: Uncontrolled Resource Consumption' + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://golang.org/pkg/io/#CopyN + - https://github.com/securego/gosec/blob/master/rules/decompression-bomb.go + semgrep.dev: + rule: + origin: community + r_id: 9105 + rule_id: oqUeqn + rv_id: 945606 + url: + https://semgrep.dev/playground/r/JdTDye5/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + version_id: JdTDye5 + shortlink: https://sg.run/RodK + source: https://semgrep.dev/r/go.lang.security.decompression_bomb.potential-dos-via-decompression-bomb + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Denial-of-Service (DoS) + patterns: + - pattern-either: + - pattern: io.Copy(...) + - pattern: io.CopyBuffer(...) + - pattern-either: + - pattern-inside: "gzip.NewReader(...)\n...\n" + - pattern-inside: "zlib.NewReader(...)\n...\n" + - pattern-inside: "zlib.NewReaderDict(...)\n...\n" + - pattern-inside: "bzip2.NewReader(...)\n...\n" + - pattern-inside: "flate.NewReader(...)\n...\n" + - pattern-inside: "flate.NewReaderDict(...)\n...\n" + - pattern-inside: "lzw.NewReader(...)\n...\n" + - pattern-inside: "tar.NewReader(...)\n...\n" + - pattern-inside: "zip.NewReader(...)\n...\n" + - pattern-inside: "zip.OpenReader(...)\n...\n" + severity: WARNING +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, which can lead to security + vulnerabilities (CWE-502). Use a concrete struct type instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/502.html + semgrep.dev: + rule: + origin: community + r_id: 274359 + rule_id: 4bUAQDG + rv_id: 1409387 + url: + https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + version_id: ZRTDkjk + shortlink: https://sg.run/6WbKL + source: + https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + subcategory: + - vuln + technology: + - go + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-either: + - pattern: "var $VAR interface{}\n...\njson.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nyaml.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nxml.Unmarshal($DATA, &$VAR)\n" + severity: WARNING +- fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + languages: + - go + message: '`Clean` is not intended to sanitize against path traversal attacks. This function is for finding the shortest + path name equivalent to the given input. Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + semgrep.dev: + rule: + origin: community + r_id: 18235 + rule_id: qNUQJe + rv_id: 1262967 + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + version_id: jQTn5Bj + shortlink: https://sg.run/ZKzw + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Path Traversal + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: "\"/\" + ...\n" + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.open-redirect.open-redirect + languages: + - go + message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This can lead to open redirect + vulnerabilities, potentially allowing attackers to redirect users to malicious web sites. It is recommend where + possible to not allow user-input to craft the redirect URL. When user-input is necessary to craft the request, it is + recommended to follow OWASP best practices to restrict the URL to domains in an allowlist. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + description: An HTTP redirect was found to be crafted from user-input leading to an open redirect vulnerability + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html + semgrep.dev: + rule: + origin: community + r_id: 113619 + rule_id: DbU6RlN + rv_id: 945608 + url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect + version_id: GxTP7J7 + shortlink: https://sg.run/2ZW45 + source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Open Redirect + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: http.Redirect($W, $REQ, $URL, ...) + - focus-metavariable: $URL + requires: INPUT and not CLEAN + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + $INPUT\n" + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + requires: INPUT + severity: WARNING +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. Use the `html/template` package which will safely render HTML + instead, or inspect that the HTML is rendered safely. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 14443 + rule_id: PeUonQ + rv_id: 1262968 + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + version_id: 1QTyp2p + shortlink: https://sg.run/3r1G + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: WARNING +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) or a safe library. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + semgrep.dev: + rule: + origin: community + r_id: 14689 + rule_id: PeUoqy + rv_id: 1409388 + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + version_id: nWTQ5qD + shortlink: https://sg.run/PbEq + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - go + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: "($X: bool)\n" + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\";\n...\n" + - pattern: $VAR += ... + - patterns: + - pattern-inside: "var $SB strings.Builder\n...\n" + - pattern-inside: "$SB.WriteString(\"$SQLSTR\")\n...\n$SB.String(...)\n" + - pattern: "$SB.WriteString(...)\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can lead to Server-Side Request Forgery + (SSRF) vulnerabilities, potentially exposing sensitive data. It is recommend where possible to not allow user-input + to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to + craft the request, it is recommended to follow OWASP best practices to prevent abuse, including using an allowlist. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + semgrep.dev: + rule: + origin: community + r_id: 14391 + rule_id: AbUQLr + rv_id: 1262970 + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + version_id: yeTxpOj + shortlink: https://sg.run/5DjW + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$CLIENT := &http.Client{...}\n...\n" + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: "http.NewRequest(\"$METHOD\", $URL, ...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + requires: INPUT and not CLEAN + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + $INPUT\n" + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + requires: INPUT + severity: WARNING +- id: go.lang.security.reverseproxy-director.reverseproxy-director + languages: + - go + message: ReverseProxy can remove headers added by Director. Consider using ReverseProxy.Rewrite instead of + ReverseProxy.Director. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-115: Misinterpretation of Input' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://github.com/golang/go/issues/50580 + semgrep.dev: + rule: + origin: community + r_id: 146567 + rule_id: zdUKzzA + rv_id: 945612 + url: https://semgrep.dev/playground/r/DkTNpvx/go.lang.security.reverseproxy-director.reverseproxy-director + version_id: DkTNpvx + shortlink: https://sg.run/9AYYR + source: https://semgrep.dev/r/go.lang.security.reverseproxy-director.reverseproxy-director + subcategory: + - audit + technology: + - go + vulnerability_class: + - Other + patterns: + - pattern-inside: "import \"net/http/httputil\"\n...\n" + - pattern-either: + - pattern: $PROXY.Director = $FUNC + - patterns: + - pattern-inside: "httputil.ReverseProxy{\n ...\n}\n" + - pattern: "Director: $FUNC\n" + severity: WARNING +- id: go.lang.security.shared-url-struct-mutation.shared-url-struct-mutation + languages: + - go + message: Shared URL struct may have been accidentally mutated. Ensure that this behavior is intended. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-436: Interpretation Conflict' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://github.com/golang/go/issues/63777 + semgrep.dev: + rule: + origin: community + r_id: 146568 + rule_id: pKU1EEO + rv_id: 945613 + url: + https://semgrep.dev/playground/r/WrTEojd/go.lang.security.shared-url-struct-mutation.shared-url-struct-mutation + version_id: WrTEojd + shortlink: https://sg.run/yyEEd + source: https://semgrep.dev/r/go.lang.security.shared-url-struct-mutation.shared-url-struct-mutation + subcategory: + - audit + technology: + - go + vulnerability_class: + - Other + patterns: + - pattern-inside: "import \"net/url\"\n...\n" + - pattern-not-inside: "... = url.Parse(...)\n...\n" + - pattern-not-inside: "... = url.ParseRequestURI(...)\n...\n" + - pattern-not-inside: "... = url.URL{...}\n...\n" + - pattern-not-inside: "var $URL *$X.URL\n...\n" + - pattern-either: + - pattern: $URL.RawQuery = ... + - pattern: $URL.Path = ... + - pattern: $URL.RawPath = ... + - pattern: $URL.Fragment = ... + - pattern: $URL.RawFragment = ... + - pattern: $URL.Scheme = ... + - pattern: $URL.Opaque = ... + - pattern: $URL.Host = ... + - pattern: $URL.User = ... + - metavariable-pattern: + metavariable: $URL + patterns: + - pattern-not: $X.$Y + - pattern-not: $X[...] + severity: WARNING +- id: go.lang.security.zip.path-traversal-inside-zip-extraction + languages: + - go + message: File traversal when extracting zip archive + metadata: + category: security + confidence: LOW + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9106 + rule_id: zdUkoR + rv_id: 1262971 + url: https://semgrep.dev/playground/r/rxTAK1Z/go.lang.security.zip.path-traversal-inside-zip-extraction + version_id: rxTAK1Z + shortlink: https://sg.run/Av64 + source: https://semgrep.dev/r/go.lang.security.zip.path-traversal-inside-zip-extraction + source_rule_url: https://github.com/securego/gosec/issues/205 + subcategory: + - audit + technology: + - go + vulnerability_class: + - Path Traversal + pattern: "reader, $ERR := zip.OpenReader($ARCHIVE)\n...\nfor _, $FILE := range reader.File {\n ...\n path := filepath.Join($TARGET, + $FILE.Name)\n ...\n}\n" + severity: WARNING diff --git a/.semgrep/registry/golang.yaml b/.semgrep/registry/golang.yaml new file mode 100644 index 0000000..a1190ba --- /dev/null +++ b/.semgrep/registry/golang.yaml @@ -0,0 +1,2122 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/golang +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: go.aws-lambda.security.database-sqli.database-sqli + languages: + - go + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable + is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or + prepared statements instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' calls. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pkg.go.dev/database/sql#DB.Query + semgrep.dev: + rule: + origin: community + r_id: 18232 + rule_id: WAUdJ7 + rv_id: 1262909 + url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli + version_id: BjTkZkQ + shortlink: https://sg.run/e5e8 + source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli + subcategory: + - vuln + technology: + - aws-lambda + - database + - sql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.Exec($QUERY,...) + - pattern: $DB.ExecContent($QUERY,...) + - pattern: $DB.Query($QUERY,...) + - pattern: $DB.QueryContext($QUERY,...) + - pattern: $DB.QueryRow($QUERY,...) + - pattern: $DB.QueryRowContext($QUERY,...) + - pattern-inside: "import \"database/sql\"\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - patterns: + - pattern-inside: "func $HANDLER($EVENT $TYPE) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - pattern-not-inside: "func $HANDLER($EVENT context.Context) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - focus-metavariable: $EVENT + severity: WARNING +- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - go + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18233 + rule_id: 0oUwqg + rv_id: 1262910 + url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: DkTRbRL + shortlink: https://sg.run/vX3Y + source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - pattern: strconv.Atoi(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: "\"$SQLSTR\" + ...\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + - pattern-not-inside: "log.$PRINT(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - patterns: + - pattern-inside: "func $HANDLER($EVENT $TYPE) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - pattern-not-inside: "func $HANDLER($EVENT context.Context) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - focus-metavariable: $EVENT + severity: ERROR +- id: go.gorilla.security.audit.handler-assignment-from-multiple-sources.handler-assignment-from-multiple-sources + languages: + - go + message: "Variable $VAR is assigned from two different sources: '$Y' and '$R'. Make sure this is intended, as this could + cause logic bugs if they are treated as they are the same object." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-289: Authentication Bypass by Alternate Name' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://cwe.mitre.org/data/definitions/289.html + semgrep.dev: + rule: + origin: community + r_id: 9085 + rule_id: WAUoBk + rv_id: 945538 + url: + https://semgrep.dev/playground/r/ZRT35xJ/go.gorilla.security.audit.handler-assignment-from-multiple-sources.handler-assignment-from-multiple-sources + version_id: ZRT35xJ + shortlink: https://sg.run/gL3y + source: + https://semgrep.dev/r/go.gorilla.security.audit.handler-assignment-from-multiple-sources.handler-assignment-from-multiple-sources + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Improper Authentication + mode: taint + pattern-sinks: + - patterns: + - pattern: "$Y, err := store.Get(...)\n...\n$VAR := $Y.Values[...]\n...\n$VAR = $R\n" + - focus-metavariable: $R + - patterns: + - pattern: "$Y, err := store.Get(...)\n...\nvar $VAR $INT = $Y.Values[\"...\"].($INT)\n...\n$VAR = $R\n" + - focus-metavariable: $R + pattern-sources: + - patterns: + - pattern-inside: "func $HANDLER(..., $R *http.Request, ...) {\n ...\n}\n" + - focus-metavariable: $R + - pattern-either: + - pattern: $R.query + severity: WARNING +- fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + languages: + - go + message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs + the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' + flag by setting 'HttpOnly' to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + semgrep.dev: + rule: + origin: community + r_id: 9088 + rule_id: qNUj6g + rv_id: 1262911 + url: + https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + version_id: WrTqKqe + shortlink: https://sg.run/4xJZ + source: + https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "&sessions.Options{\n ...,\n HttpOnly: true,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + languages: + - go + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the + client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' + to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + semgrep.dev: + rule: + origin: community + r_id: 9089 + rule_id: lBU9kw + rv_id: 1262912 + url: + https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + version_id: 0bTKzKk + shortlink: https://sg.run/PJdE + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "&sessions.Options{\n ...,\n Secure: true,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (SameSite\s*:\s+)http.SameSiteNoneMode + replacement: \1http.SameSiteDefaultMode + id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + languages: + - go + message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting SameSite to Lax, Strict or + Default for enhanced security. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://pkg.go.dev/github.com/gorilla/sessions#Options + semgrep.dev: + rule: + origin: community + r_id: 133074 + rule_id: YGUpGd4 + rv_id: 1262913 + url: + https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + version_id: K3TKkKB + shortlink: https://sg.run/x8Nwj + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-inside: "&sessions.Options{\n ...,\n SameSite: http.SameSiteNoneMode,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + languages: + - go + message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee that the connection accepted by the WebSocket + is from a trusted origin domain. Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" + documentation: "A CheckOrigin function should carefully validate the request origin to prevent cross-site request forgery."' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader + semgrep.dev: + rule: + origin: community + r_id: 18430 + rule_id: ReUKdz + rv_id: 1262914 + url: + https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + version_id: qkTR7RP + shortlink: https://sg.run/xXpz + source: + https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "import (\"github.com/gorilla/websocket\")\n...\n" + - patterns: + - pattern-not-inside: "$UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...}\n...\n" + - pattern-not-inside: "$UPGRADER.CheckOrigin = $FN2\n...\n" + - pattern: "$UPGRADER.Upgrade(...)\n" + severity: WARNING +- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + languages: + - go + message: Detected usage of dangerous method $METHOD which does not escape inputs (see link in references). If the + argument is user-controlled, this can lead to SQL injection. When using $METHOD function, do not trust + user-submitted data and only allow approved list of input (possibly, use an allowlist approach). + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://gorm.io/docs/security.html#SQL-injection-Methods + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 24693 + rule_id: AbU5o3 + rv_id: 1262915 + url: + https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + version_id: l4TJRJK + shortlink: https://sg.run/R4qg + source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + subcategory: + - vuln + technology: + - gorm + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: "($X: bool)\n" + pattern-sinks: + - patterns: + - pattern-inside: "import (\"gorm.io/gorm\")\n...\n" + - patterns: + - pattern-inside: "func $VAL(..., $GORM *gorm.DB,... ) {\n ...\n}\n" + - pattern-either: + - pattern: "$GORM. ... .$METHOD($VALUE)\n" + - pattern: "$DB := $GORM. ... .$ANYTHING(...)\n...\n$DB. ... .$METHOD($VALUE)\n" + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: WARNING +- fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) + id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + languages: + - go + message: "Found an insecure gRPC connection using 'grpc.WithInsecure()'. This creates a connection without encryption to + a gRPC server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Instead, establish + a secure connection with an SSL certificate using the 'grpc.WithTransportCredentials()' function. You can create a create + credentials using a 'tls.Config{}' struct with 'credentials.NewTLS()'. The final fix looks like this: 'grpc.WithTransportCredentials(credentials.NewTLS())'." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + semgrep.dev: + rule: + origin: community + r_id: 9090 + rule_id: PeUZ4X + rv_id: 1262916 + url: + https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + version_id: YDTZeZB + shortlink: https://sg.run/J9yZ + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + subcategory: + - audit + technology: + - grpc + vulnerability_class: + - Other + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + severity: ERROR +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + languages: + - go + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. This allows for a + connection without encryption to this server. A malicious attacker could tamper with the gRPC message, which could + compromise the machine. Include credentials derived from an SSL certificate in order to create a secure gRPC + connection. You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", "cert.key")'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + semgrep.dev: + rule: + origin: community + r_id: 9091 + rule_id: JDUy0B + rv_id: 1262917 + url: + https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + version_id: 6xT2923 + shortlink: https://sg.run/5Q5l + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + subcategory: + - audit + technology: + - grpc + vulnerability_class: + - Other + mode: taint + pattern-sinks: + - pattern: grpc.NewServer($OPT, ...) + requires: OPTIONS and not CREDS + - pattern: grpc.NewServer() + requires: EMPTY_CONSTRUCTOR + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + severity: ERROR +- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + languages: + - go + message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` unless you know what + you're doing This method parses the token but doesn't validate the signature. It's only ever useful in cases where + you know the signature is valid (because it has been checked previously in the stack) and you want to extract values + from it. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + semgrep.dev: + rule: + origin: community + r_id: 9094 + rule_id: ReUgJJ + rv_id: 1262918 + url: + https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + version_id: o5TbDbq + shortlink: https://sg.run/Av66 + source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Improper Authentication + patterns: + - pattern-inside: "import \"github.com/dgrijalva/jwt-go\"\n...\n" + - pattern: "$JWT.ParseUnverified(...)\n" + severity: WARNING +- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + languages: + - go + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9092 + rule_id: 5rUOWQ + rv_id: 1262919 + url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + version_id: zyTb2bz + shortlink: https://sg.run/Gej1 + source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "import \"github.com/golang-jwt/jwt\"\n...\n" + - pattern-inside: "import \"github.com/dgrijalva/jwt-go\"\n...\n" + - pattern-either: + - pattern: "jwt.SigningMethodNone\n" + - pattern: jwt.UnsafeAllowNoneSignatureType + severity: ERROR +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + languages: + - go + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9093 + rule_id: GdU7Ny + rv_id: 1262920 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + version_id: pZT0305 + shortlink: https://sg.run/Rod2 + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + subcategory: + - vuln + technology: + - jwt + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$TOKEN.SignedString($F)\n" + - focus-metavariable: $F + pattern-sources: + - patterns: + - pattern-inside: "[]byte(\"$F\")\n" + severity: WARNING +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + languages: + - go + message: The package `net/http/cgi` is on the import blocklist. The package is vulnerable to httpoxy attacks + (CVE-2015-5386). It is recommended to use `net/http` or a web framework to build a web application instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://godoc.org/golang.org/x/crypto/sha3 + semgrep.dev: + rule: + origin: community + r_id: 9113 + rule_id: yyUnov + rv_id: 1262921 + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + version_id: 2KTv2vJ + shortlink: https://sg.run/l2gj + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import \"net/http/cgi\"\n...\n" + - pattern: "cgi.$FUNC(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + languages: + - go + message: Disabled host key verification detected. This allows man-in-the-middle attacks. Use the + 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. See + https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to learn more about the problem and how to + fix it. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + semgrep.dev: + rule: + origin: community + r_id: 9114 + rule_id: r6UrW9 + rv_id: 1262922 + url: + https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + version_id: X0TzyzN + shortlink: https://sg.run/Yv6X + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Improper Authentication + pattern: ssh.InsecureIgnoreHostKey() + severity: WARNING +- fix: "crypto/rand\n" + id: go.lang.security.audit.crypto.math_random.math-random-used + languages: + - go + message: Do not use `math/rand`. Use `crypto/rand` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + semgrep.dev: + rule: + origin: community + r_id: 9115 + rule_id: bwUwy8 + rv_id: 1262923 + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + version_id: jQTn5nj + shortlink: https://sg.run/6nK6 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "import $RAND \"$MATH\"\n" + - pattern: "import \"$MATH\"\n" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: "...\nrand.$FUNC(...)\n" + - pattern-inside: "...\n$RAND.$FUNC(...)\n" + - focus-metavariable: + - $MATH + severity: WARNING +- fix: "tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }\n" + id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + languages: + - go + message: "`MinVersion` is missing from this TLS configuration. By default, as of Go 1.22, TLS 1.2 is currently used as + the minimum. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where + it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer + 10), it may be necessary to enable TLS 1.0 to provide support. Add `MinVersion: tls.VersionTLS13' to the TLS configuration + to bump the minimum version to TLS 1.3." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9116 + rule_id: NbUk4X + rv_id: 1262924 + url: + https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + version_id: 1QTypyp + shortlink: https://sg.run/oxEN + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "tls.Config{ $...CONF }\n" + - pattern-not: "tls.Config{..., MinVersion: ..., ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + languages: + - go + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151749 + rule_id: GdUvElR + rv_id: 1262925 + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + version_id: 9lT4b4w + shortlink: https://sg.run/ReJwY + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - patterns: + - pattern-inside: "import \"crypto/sha256\"\n...\n" + - pattern-either: + - pattern: "sha256.New224()\n" + - pattern: "sha256.Sum224(...)\n" + - patterns: + - pattern-inside: "import \"golang.org/x/crypto/sha3\"\n...\n" + - pattern-either: + - pattern: "sha3.New224()\n" + - pattern: "sha3.Sum224(...)\n" + severity: WARNING +- fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + languages: + - go + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, SSLv3 will be removed. Instead, + use 'tls.VersionTLS13'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9117 + rule_id: kxUkJ2 + rv_id: 1262926 + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + version_id: yeTxpxj + shortlink: https://sg.run/zvE1 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' + severity: WARNING +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + languages: + - go + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered weak. Use the function + 'tls.CipherSuites()' to get a list of good cipher suites. See + https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other cipher suites to use. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + semgrep.dev: + rule: + origin: community + r_id: 9118 + rule_id: wdUJYk + rv_id: 1262927 + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + version_id: rxTAKAZ + shortlink: https://sg.run/px8N + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + languages: + - go + message: Detected DES cipher algorithm which is insecure. The algorithm is considered weak and has been deprecated. + Use AES instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9121 + rule_id: eqU8B3 + rv_id: 1262930 + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + version_id: kbTzGzA + shortlink: https://sg.run/jREA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/des\"\n...\n" + - pattern-either: + - pattern: "des.NewTripleDESCipher(...)\n" + - pattern: "des.NewCipher(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + languages: + - go + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9119 + rule_id: x8Un6q + rv_id: 1262928 + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + version_id: bZT535Y + shortlink: https://sg.run/2xB5 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/md5\"\n...\n" + - pattern-either: + - pattern: "md5.New()\n" + - pattern: "md5.Sum(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + languages: + - go + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many known vulnerabilities. Use AES + instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9122 + rule_id: v8Unl0 + rv_id: 1262931 + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + version_id: w8TRoRQ + shortlink: https://sg.run/1ZAD + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/rc4\"\n...\n" + - pattern: rc4.NewCipher(...) + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + languages: + - go + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9120 + rule_id: OrU31O + rv_id: 1262929 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + version_id: NdTzyz1 + shortlink: https://sg.run/XBYA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/sha1\"\n...\n" + - pattern-either: + - pattern: "sha1.New()\n" + - pattern: "sha1.Sum(...)\n" + severity: WARNING +- fix: "2048\n" + id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + languages: + - go + message: RSA keys should be at least 2048 bits + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 9123 + rule_id: d8UjY3 + rv_id: 1262932 + url: + https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + version_id: xyTjz8L + shortlink: https://sg.run/9oY4 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "rsa.GenerateKey(..., $BITS)\n" + - pattern: "rsa.GenerateMultiPrimeKey(..., $BITS)\n" + - metavariable-comparison: + comparison: $BITS < 2048 + metavariable: $BITS + - focus-metavariable: + - $BITS + severity: WARNING +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + languages: + - go + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9108 + rule_id: 2ZUb8l + rv_id: 1262934 + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + version_id: e1Tyjeg + shortlink: https://sg.run/Dorj + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - patterns: + - pattern: "exec.Cmd {...,Path: $CMD,...}\n" + - pattern-not: "exec.Cmd {...,Path: \"...\",...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: $ARGS,...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{...},...}\n" + - pattern-not-inside: "$ARGS = []string{\"...\",...};\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n$ARGS = []string{$CMD,...};\n...\n" + - pattern-not-inside: "$CMD = exec.LookPath(\"...\");\n...\n$ARGS = []string{$CMD,...};\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,...},...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",...},...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern-either: + - pattern: "exec.Cmd {...,Args: []string{\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$EXE,...},...}\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,\"-c\",$EXE,...},...}\n" + - pattern-inside: "$CMD,$ERR := exec.LookPath(\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\");\n...\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",\"...\",\"...\",...},...}\n" + - pattern-not-inside: "$EXE = \"...\";\n...\n" + - pattern-inside: "import \"os/exec\"\n...\n" + severity: ERROR +- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - go + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can + use the `golang.org/x/crypto/bcrypt` package. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://pkg.go.dev/golang.org/x/crypto/bcrypt + semgrep.dev: + rule: + origin: community + r_id: 14688 + rule_id: 4bU1Wj + rv_id: 1262938 + url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: nWT2L9r + shortlink: https://sg.run/4eOE + source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5.New + - pattern: md5.Sum + severity: WARNING +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + languages: + - go + message: Detected a network listener listening on 0.0.0.0 or an empty string. This could unexpectedly expose the + server publicly as it binds to all available interfaces. Instead, specify another IP address that is not 0.0.0.0 nor + the empty string. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9125 + rule_id: nJUz3J + rv_id: 1262939 + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + version_id: ExTExoK + shortlink: https://sg.run/rdE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) + severity: WARNING +- fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + languages: + - go + message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs + the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' + flag by setting 'HttpOnly' to 'true' in the Cookie. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9126 + rule_id: EwU2Z6 + rv_id: 1262940 + url: + https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + version_id: 7ZTE3BW + shortlink: https://sg.run/b73e + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n HttpOnly: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + languages: + - go + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the + client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' + to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9127 + rule_id: 7KUQ8X + rv_id: 1262941 + url: + https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + version_id: LjTkgGE + shortlink: https://sg.run/N4G7 + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n Secure: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + languages: + - go + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep could not find a static definition + for '$TRACE'. Dynamic ClientTraces are dangerous because they deserialize function code to run when certain Request + events occur, which could lead to code being run without your knowledge. Ensure that your ClientTrace is statically + defined. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + semgrep.dev: + rule: + origin: community + r_id: 9128 + rule_id: L1Uyjp + rv_id: 1262942 + url: + https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + version_id: 8KT5rNv + shortlink: https://sg.run/kXEK + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-not-inside: "package $PACKAGE\n...\n&httptrace.ClientTrace { ... }\n...\n" + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + languages: + - go + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' does not escape contents. Be + absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may + have a XSS vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + semgrep.dev: + rule: + origin: community + r_id: 9129 + rule_id: 8GUjDW + rv_id: 1262943 + url: + https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + version_id: gETB7Pe + shortlink: https://sg.run/weE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.HTML($OTHER, ...)" + severity: WARNING +- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + languages: + - go + message: "Detected usage of 'http.FileServer' as handler: this allows directory listing and an attacker could navigate through + directories looking for sensitive files. Be sure to disable directory listing or restrict access to specific directories/files." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/OWASP/Go-SCP + - https://cwe.mitre.org/data/definitions/548.html + semgrep.dev: + rule: + origin: community + r_id: 21300 + rule_id: 5rU9JO + rv_id: 1262944 + url: + https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + version_id: QkTGqX0 + shortlink: https://sg.run/4R8x + source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern-inside: "$FS := http.FileServer(...)\n...\n" + - pattern-either: + - pattern: "http.ListenAndServe(..., $FS)\n" + - pattern: "http.ListenAndServeTLS(..., $FS)\n" + - pattern: "http.Handle(..., $FS)\n" + - pattern: "http.HandleFunc(..., $FS)\n" + - patterns: + - pattern: "http.$FN(..., http.FileServer(...))\n" + - metavariable-regex: + metavariable: $FN + regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc) + severity: WARNING +- fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + id: go.lang.security.audit.net.use-tls.use-tls + languages: + - go + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See + https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + semgrep.dev: + rule: + origin: community + r_id: 9134 + rule_id: PeUZ8X + rv_id: 1262948 + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + version_id: JdTzxkn + shortlink: https://sg.run/dKbY + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern: http.ListenAndServe($ADDR, $HANDLER) + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + languages: + - go + message: Found data going from url query parameters into formatted data written to ResponseWriter. This could be XSS + and should not be done. If you must do this, ensure your data is sanitized or escaped. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9135 + rule_id: JDUyXB + rv_id: 1262949 + url: + https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + version_id: 5PTo1qr + shortlink: https://sg.run/Zvon + source: + https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "func $FUNC(..., $W http.ResponseWriter, ...) {\n ...\n var $TEMPLATE = \"...\"\n ...\n $W.Write([]byte(fmt.$PRINTF($TEMPLATE, + ...)), ...)\n ...\n}\n" + - pattern-either: + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n\ + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $INTERM, + ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $DATA, ...)))\n" + severity: WARNING +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, which can lead to security + vulnerabilities (CWE-502). Use a concrete struct type instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/502.html + semgrep.dev: + rule: + origin: community + r_id: 274359 + rule_id: 4bUAQDG + rv_id: 1409387 + url: + https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + version_id: ZRTDkjk + shortlink: https://sg.run/6WbKL + source: + https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + subcategory: + - vuln + technology: + - go + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-either: + - pattern: "var $VAR interface{}\n...\njson.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nyaml.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nxml.Unmarshal($DATA, &$VAR)\n" + severity: WARNING +- fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + languages: + - go + message: '`Clean` is not intended to sanitize against path traversal attacks. This function is for finding the shortest + path name equivalent to the given input. Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + semgrep.dev: + rule: + origin: community + r_id: 18235 + rule_id: qNUQJe + rv_id: 1262967 + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + version_id: jQTn5Bj + shortlink: https://sg.run/ZKzw + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Path Traversal + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: "\"/\" + ...\n" + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.open-redirect.open-redirect + languages: + - go + message: An HTTP redirect was found to be crafted from user-input `$REQUEST`. This can lead to open redirect + vulnerabilities, potentially allowing attackers to redirect users to malicious web sites. It is recommend where + possible to not allow user-input to craft the redirect URL. When user-input is necessary to craft the request, it is + recommended to follow OWASP best practices to restrict the URL to domains in an allowlist. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + description: An HTTP redirect was found to be crafted from user-input leading to an open redirect vulnerability + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://knowledge-base.secureflag.com/vulnerabilities/unvalidated_redirects___forwards/open_redirect_go_lang.html + semgrep.dev: + rule: + origin: community + r_id: 113619 + rule_id: DbU6RlN + rv_id: 945608 + url: https://semgrep.dev/playground/r/GxTP7J7/go.lang.security.injection.open-redirect.open-redirect + version_id: GxTP7J7 + shortlink: https://sg.run/2ZW45 + source: https://semgrep.dev/r/go.lang.security.injection.open-redirect.open-redirect + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Open Redirect + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: http.Redirect($W, $REQ, $URL, ...) + - focus-metavariable: $URL + requires: INPUT and not CLEAN + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + $INPUT\n" + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + requires: INPUT + severity: WARNING +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. Use the `html/template` package which will safely render HTML + instead, or inspect that the HTML is rendered safely. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 14443 + rule_id: PeUonQ + rv_id: 1262968 + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + version_id: 1QTyp2p + shortlink: https://sg.run/3r1G + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: WARNING +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) or a safe library. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + semgrep.dev: + rule: + origin: community + r_id: 14689 + rule_id: PeUoqy + rv_id: 1409388 + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + version_id: nWTQ5qD + shortlink: https://sg.run/PbEq + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - go + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: "($X: bool)\n" + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\";\n...\n" + - pattern: $VAR += ... + - patterns: + - pattern-inside: "var $SB strings.Builder\n...\n" + - pattern-inside: "$SB.WriteString(\"$SQLSTR\")\n...\n$SB.String(...)\n" + - pattern: "$SB.WriteString(...)\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can lead to Server-Side Request Forgery + (SSRF) vulnerabilities, potentially exposing sensitive data. It is recommend where possible to not allow user-input + to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to + craft the request, it is recommended to follow OWASP best practices to prevent abuse, including using an allowlist. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + semgrep.dev: + rule: + origin: community + r_id: 14391 + rule_id: AbUQLr + rv_id: 1262970 + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + version_id: yeTxpOj + shortlink: https://sg.run/5DjW + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$CLIENT := &http.Client{...}\n...\n" + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: "http.NewRequest(\"$METHOD\", $URL, ...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + requires: INPUT and not CLEAN + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + $INPUT\n" + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + requires: INPUT + severity: WARNING +- id: go.lang.security.reverseproxy-director.reverseproxy-director + languages: + - go + message: ReverseProxy can remove headers added by Director. Consider using ReverseProxy.Rewrite instead of + ReverseProxy.Director. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-115: Misinterpretation of Input' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://github.com/golang/go/issues/50580 + semgrep.dev: + rule: + origin: community + r_id: 146567 + rule_id: zdUKzzA + rv_id: 945612 + url: https://semgrep.dev/playground/r/DkTNpvx/go.lang.security.reverseproxy-director.reverseproxy-director + version_id: DkTNpvx + shortlink: https://sg.run/9AYYR + source: https://semgrep.dev/r/go.lang.security.reverseproxy-director.reverseproxy-director + subcategory: + - audit + technology: + - go + vulnerability_class: + - Other + patterns: + - pattern-inside: "import \"net/http/httputil\"\n...\n" + - pattern-either: + - pattern: $PROXY.Director = $FUNC + - patterns: + - pattern-inside: "httputil.ReverseProxy{\n ...\n}\n" + - pattern: "Director: $FUNC\n" + severity: WARNING diff --git a/.semgrep/registry/javascript.yaml b/.semgrep/registry/javascript.yaml new file mode 100644 index 0000000..e67a1a5 --- /dev/null +++ b/.semgrep/registry/javascript.yaml @@ -0,0 +1,5370 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/javascript +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + languages: + - javascript + - typescript + message: Use of angular.element can lead to XSS if user-input is treated as part of the HTML element within `$SINK`. + It is recommended to contextually output encode user-input, before inserting into `$SINK`. If the HTML needs to be + preserved it is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 21503 + rule_id: GdUP71 + rv_id: 1263091 + url: + https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + version_id: 44TEj8L + shortlink: https://sg.run/5AQ0 + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + subcategory: + - vuln + technology: + - angularjs + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "angular.element(...). ... .$SINK($QUERY)\n" + - pattern-inside: "$ANGULAR = angular.element(...)\n...\n$ANGULAR. ... .$SINK($QUERY)\n" + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern: window.location.search + - pattern: window.document.location.search + - pattern: document.location.search + - pattern: location.search + - pattern: $location.search(...) + - patterns: + - pattern-either: + - pattern: $DECODE(<... location.hash ...>) + - pattern: $DECODE(<... window.location.hash ...>) + - pattern: $DECODE(<... document.location.hash ...>) + - pattern: $DECODE(<... location.href ...>) + - pattern: $DECODE(<... window.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.URL ...>) + - pattern: $DECODE(<... window.document.URL ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... $location.absUrl() ...>) + - pattern: $DECODE(<... $location.url() ...>) + - pattern: $DECODE(<... $location.hash() ...>) + - metavariable-regex: + metavariable: $DECODE + regex: ^(unescape|decodeURI|decodeURIComponent)$ + - patterns: + - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|delete|head|jsonp|post|put|patch) + - pattern: $RES.data + severity: WARNING +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + languages: + - javascript + - typescript + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) in an AngularJS application could + provide additional attack surface for XSS vulnerabilities. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 9227 + rule_id: EwU20Z + rv_id: 1263094 + url: + https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + version_id: 5PTo1EW + shortlink: https://sg.run/N4DG + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + subcategory: + - vuln + technology: + - angular + vulnerability_class: + - Cross-Site-Scripting (XSS) + pattern: "$sceProvider.enabled(false);\n" + severity: ERROR +- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + languages: + - javascript + - typescript + message: The use of $sce.trustAs can be dangerous if unsanitized user input flows through this API. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 9231 + rule_id: gxU1QX + rv_id: 1263098 + url: + https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + version_id: BjTkZv0 + shortlink: https://sg.run/OPW2 + source: + https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + subcategory: + - vuln + technology: + - angular + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - pattern: $sce.trustAs(...) + - pattern: $sce.trustAsHtml(...) + pattern-sources: + - patterns: + - pattern-inside: "app.controller(..., function($scope,$sce) {\n...\n});\n" + - pattern: $scope.$X + severity: WARNING +- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + languages: + - javascript + - typescript + message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends selecting Argon2id unless you can + guarantee an adversary has no direct access to the computing environment. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + - https://eprint.iacr.org/2016/759.pdf + - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf + - https://datatracker.ietf.org/doc/html/rfc9106#section-4 + semgrep.dev: + rule: + origin: community + r_id: 20150 + rule_id: DbU2X8 + rv_id: 1263103 + url: + https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + version_id: qkTR7Jk + shortlink: https://sg.run/ALq4 + source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + subcategory: + - vuln + technology: + - argon2 + - cryptography + vulnerability_class: + - Insecure Hashing Algorithm + mode: taint + pattern-sanitizers: + - patterns: + - pattern: '{type: $ARGON.argon2id}' + pattern-sinks: + - patterns: + - pattern: "$Y\n" + - pattern-inside: "$ARGON.hash(...,$Y)\n" + pattern-sources: + - patterns: + - pattern-inside: "$ARGON = require('argon2');\n...\n" + - pattern: "{type: ...}\n" + severity: WARNING +- id: javascript.aws-lambda.security.detect-child-process.detect-child-process + languages: + - javascript + - typescript + message: Allowing spawning arbitrary programs or running shell processes with arbitrary arguments may end up in a + command injection vulnerability. Try to avoid non-literal values for the command string. If it is not possible, then + do not let running arbitrary commands, use a white list for inputs. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18248 + rule_id: r6UDNQ + rv_id: 1263105 + url: + https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process + version_id: YDTZe4o + shortlink: https://sg.run/Ggoq + source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process + subcategory: + - vuln + technology: + - javascript + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: exec($CMD,...) + - pattern: execSync($CMD,...) + - pattern: spawn($CMD,...) + - pattern: spawnSync($CMD,...) + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-either: + - pattern-inside: "require('child_process')\n...\n" + - pattern-inside: "import 'child_process'\n...\n" + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + languages: + - javascript + - typescript + message: Detected DynamoDB query params that are tainted by `$EVENT` object. This could lead to NoSQL injection if the + variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from + `$EVENT` directly to DynamoDB client. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 21320 + rule_id: 0oU1xk + rv_id: 945766 + url: + https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + version_id: GxTP7gN + shortlink: https://sg.run/X1e4 + source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + subcategory: + - vuln + technology: + - javascript + - aws-lambda + - dynamodb + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "{...}\n" + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern: "$DC.$METHOD($SINK, ...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: + (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) + - pattern-either: + - pattern-inside: "$DC = new $AWS.DocumentClient(...);\n...\n" + - pattern-inside: "$DC = new $AWS.DynamoDB(...);\n...\n" + - pattern-inside: "$DC = new DynamoDBClient(...);\n...\n" + - pattern-inside: "$DC = DynamoDBDocumentClient.from(...);\n...\n" + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.aws-lambda.security.knex-sqli.knex-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `knex.raw('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + semgrep.dev: + rule: + origin: community + r_id: 18249 + rule_id: bwUBlj + rv_id: 1263106 + url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli + version_id: JdTzxKg + shortlink: https://sg.run/RgWq + source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli + subcategory: + - vuln + technology: + - aws-lambda + - knex + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $KNEX.fromRaw($QUERY, ...) + - pattern: $KNEX.whereRaw($QUERY, ...) + - pattern: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: "require('knex')\n...\n" + - pattern-inside: "import 'knex'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.npmjs.com/package/mysql2 + semgrep.dev: + rule: + origin: community + r_id: 18250 + rule_id: NbUBJ2 + rv_id: 1263107 + url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + version_id: 5PTo1En + shortlink: https://sg.run/A502 + source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - mysql + - mysql2 + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $POOL.query($QUERY, ...) + - pattern: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: "require('mysql')\n...\n" + - pattern-inside: "require('mysql2')\n...\n" + - pattern-inside: "require('mysql2/promise')\n...\n" + - pattern-inside: "import 'mysql'\n...\n" + - pattern-inside: "import 'mysql2'\n...\n" + - pattern-inside: "import 'mysql2/promise'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.pg-sqli.pg-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://node-postgres.com/features/queries + semgrep.dev: + rule: + origin: community + r_id: 18251 + rule_id: kxU25P + rv_id: 1263108 + url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli + version_id: GxTkeJL + shortlink: https://sg.run/BGKA + source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli + subcategory: + - vuln + technology: + - aws-lambda + - postgres + - pg + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: "require('pg')\n...\n" + - pattern-inside: "import 'pg'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `sequelize.query('SELECT * FROM projects WHERE status = ?', { replacements: + ['active'], type: QueryTypes.SELECT });`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sequelize.org/master/manual/raw-queries.html + semgrep.dev: + rule: + origin: community + r_id: 18252 + rule_id: wdUA5o + rv_id: 1263109 + url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + version_id: RGT0LrD + shortlink: https://sg.run/DAlP + source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + subcategory: + - vuln + technology: + - aws-lambda + - sequelize + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: "require('sequelize')\n...\n" + - pattern-inside: "import 'sequelize'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response + languages: + - javascript + - typescript + message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of + rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could + let attackers steal sensitive user data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18254 + rule_id: OrUJBY + rv_id: 1263111 + url: + https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + version_id: BjTkZ8D + shortlink: https://sg.run/0Gvj + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $BODY + - pattern-inside: "{..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... }\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - javascript + - typescript + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18483 + rule_id: PeUxwW + rv_id: 1263112 + url: + https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + version_id: DkTRbvp + shortlink: https://sg.run/Lgqr + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$HTMLSTR\" + $EXPR\n" + - pattern: "\"$HTMLSTR\".concat(...)\n" + - pattern: $UTIL.format($HTMLSTR, ...) + - pattern: format($HTMLSTR, ...) + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - patterns: + - pattern: "`...${...}...`\n" + - pattern-regex: ".*<\\w+.*\n" + - pattern-not-inside: "console.$LOG(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + languages: + - javascript + - typescript + message: The `vm` module enables compiling and running code within V8 Virtual Machine contexts. The `vm` module is not + a security mechanism. Do not use it to run untrusted code. If code passed to `vm` functions is controlled by user + input it could result in command injection. Do not let user input in `vm` functions. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18256 + rule_id: v8UOdZ + rv_id: 1263114 + url: + https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + version_id: 0bTKz9J + shortlink: https://sg.run/q9w7 + source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + subcategory: + - vuln + technology: + - javascript + - aws-lambda + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('vm');\n...\n" + - pattern-inside: "import 'vm'\n...\n" + - pattern-either: + - pattern: $VM.runInContext($X,...) + - pattern: $VM.runInNewContext($X,...) + - pattern: $VM.runInThisContext($X,...) + - pattern: $VM.compileFunction($X,...) + - pattern: new $VM.Script($X,...) + - pattern: new $VM.SourceTextModule($X,...) + - pattern: runInContext($X,...) + - pattern: runInNewContext($X,...) + - pattern: runInThisContext($X,...) + - pattern: compileFunction($X,...) + - pattern: new Script($X,...) + - pattern: new SourceTextModule($X,...) + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.browser.security.open-redirect.js-open-redirect + languages: + - javascript + - typescript + message: The application accepts potentially user-controlled input `$PROP` which can control the location of the + current window context. This can lead two types of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) + with JavaScript URIs. It is recommended to validate user-controllable input before allowing it to control the + redirection. + metadata: + asvs: + control_id: 5.5.1 Insecue Redirect + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9243 + rule_id: WAUopl + rv_id: 1263122 + url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect + version_id: pZT03x0 + shortlink: https://sg.run/3xRe + source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect + subcategory: + - vuln + technology: + - browser + vulnerability_class: + - Open Redirect + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: location.href = $SINK + - pattern: $THIS. ... .location.href = $SINK + - pattern: location.replace($SINK) + - pattern: $THIS. ... .location.replace($SINK) + - pattern: location = $SINK + - pattern: $WINDOW. ... .location = $SINK + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $SINK + patterns: + - pattern-not: "\"...\" + $VALUE\n" + - pattern-not: "`...${$VALUE}`\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "new URLSearchParams($WINDOW. ... .location.search).get('...')\n" + - pattern: "new URLSearchParams(location.search).get('...')\n" + - pattern: "new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')\n" + - pattern: "new URLSearchParams(location.hash.substring(1)).get('...')\n" + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.search)\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.search)\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1))\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.hash.substring(1))\n...\n" + - pattern: $PROPS.get('...') + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URL($WINDOW. ... .location.href)\n...\n" + - pattern-inside: "$PROPS = new URL(location.href)\n...\n" + - pattern: $PROPS.searchParams.get('...') + - patterns: + - pattern-either: + - pattern: "new URL($WINDOW. ... .location.href).searchParams.get('...')\n" + - pattern: "new URL(location.href).searchParams.get('...')\n" + severity: WARNING +- id: javascript.browser.security.raw-html-concat.raw-html-concat + languages: + - javascript + - typescript + message: User controlled data in a HTML string may result in XSS + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/xss/ + semgrep.dev: + rule: + origin: community + r_id: 9244 + rule_id: 0oU5b5 + rv_id: 1263123 + url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat + version_id: 2KTv2wp + shortlink: https://sg.run/4xAx + source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat + subcategory: + - vuln + technology: + - browser + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $STRING + $EXPR + - pattern-not: $STRING + "..." + - metavariable-pattern: + language: generic + metavariable: $STRING + patterns: + - pattern: <$TAG ... + - pattern-not: <$TAG ...>...... + - patterns: + - pattern: $EXPR + $STRING + - pattern-not: '"..." + $STRING' + - metavariable-pattern: + language: generic + metavariable: $STRING + patterns: + - pattern: '... ,...) + - pattern-not-inside: "$OPTS = <... {name:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.name = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + languages: + - javascript + - typescript + message: 'Default session middleware settings: `domain` not set. It indicates the domain of the cookie; use it to compare + against the domain of the server in which the URL is being requested. If they match, then check the path attribute next.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9269 + rule_id: ZqU5Pn + rv_id: 1263133 + url: + https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + version_id: w8TRoyd + shortlink: https://sg.run/rd41 + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{domain:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {domain:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {domain:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.domain = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.domain = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + languages: + - javascript + - typescript + message: 'Default session middleware settings: `expires` not set. Use it to set expiration date for persistent cookies.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9271 + rule_id: EwU2DZ + rv_id: 1263135 + url: + https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + version_id: O9TpxRq + shortlink: https://sg.run/N4eG + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{expires:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {expires:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {expires:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.expires = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.expires = ...;\n...\n$SESSION($OPTS,...);" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + languages: + - javascript + - typescript + message: 'Default session middleware settings: `httpOnly` not set. It ensures the cookie is sent only over HTTP(S), not + client JavaScript, helping to protect against cross-site scripting attacks.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9268 + rule_id: d8UjGo + rv_id: 1263132 + url: + https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + version_id: kbTzGev + shortlink: https://sg.run/ydBO + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{httpOnly:true}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {httpOnly:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {httpOnly:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.httpOnly = true;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.httpOnly = true;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + languages: + - javascript + - typescript + message: 'Default session middleware settings: `path` not set. It indicates the path of the cookie; use it to compare against + the request path. If this and domain match, then send the cookie in the request.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9270 + rule_id: nJUz4X + rv_id: 1263134 + url: + https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + version_id: xyTjzQD + shortlink: https://sg.run/b7pd + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{path:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {path:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {path:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.path = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.path = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + languages: + - javascript + - typescript + message: 'Default session middleware settings: `secure` not set. It ensures the browser only sends the cookie over HTTPS.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9267 + rule_id: v8Unzw + rv_id: 1263131 + url: + https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + version_id: NdTzyrv + shortlink: https://sg.run/9oKz + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{secure:true}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {secure:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {secure:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.secure = true;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.secure = true;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + languages: + - javascript + - typescript + message: No token revoking configured for `express-jwt`. A leaked token could still be used and unable to be revoked. + Consider using function as the `isRevoked` option. + metadata: + asvs: + control_id: 3.5.3 Insecure Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9272 + rule_id: 7KUQ9k + rv_id: 1263137 + url: + https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + version_id: vdT06Bg + shortlink: https://sg.run/kXNo + source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "$JWT = require('express-jwt');\n...\n" + - pattern: $JWT(...) + - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) + - pattern-not-inside: "$OPTS = <... {isRevoked:...} ...>;\n...\n$JWT($OPTS,...);" + severity: WARNING +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + languages: + - javascript + - typescript + message: The libxml library processes user-input with the `noent` attribute is set to `true` which can lead to being + vulnerable to XML External Entities (XXE) type attacks. It is recommended to set `noent` to `false` when using this + feature to ensure you are protected. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22079 + rule_id: pKUNeD + rv_id: 1263138 + url: + https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + version_id: d6TyxpX + shortlink: https://sg.run/Z75x + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + options: + interfile: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$XML = require('$IMPORT')\n...\n" + - pattern-inside: "import $XML from '$IMPORT'\n ...\n" + - pattern-inside: "import * as $XML from '$IMPORT'\n...\n" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: javascript.express.security.audit.express-open-redirect.express-open-redirect + languages: + - javascript + - typescript + message: The application redirects to a URL specified by user-supplied input `$REQ` that is not validated. This could + redirect users to malicious locations. Consider using an allow-list approach to validate URLs, or warn users they + are being redirected to a third-party website. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22081 + rule_id: X5ULkq + rv_id: 1263140 + url: + https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect + version_id: nWT2L0v + shortlink: https://sg.run/EpoP + source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Open Redirect + mode: taint + options: + symbolic_propagation: true + taint_unify_mvars: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $HTTP + regex: ^https?:\/\/$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ. ... .$VALUE) + - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ.$VALUE['...']) + - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) + - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) + - pattern: $REQ.$VALUE + - patterns: + - pattern-either: + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...']\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE}...`\n...\n" + - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" + - pattern-either: + - pattern: $RES.redirect($ASSIGN) + - pattern: $RES.redirect($ASSIGN + $...FOO) + - pattern: $RES.redirect(`${$ASSIGN}...`) + - focus-metavariable: $ASSIGN + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + languages: + - javascript + - typescript + message: Possible writing outside of the destination, make sure that the target path is nested in the intended + destination + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9273 + rule_id: L1Uyb8 + rv_id: 1263141 + url: + https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + version_id: ExTExX0 + shortlink: https://sg.run/weRn + source: + https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + subcategory: + - vuln + technology: + - express + - node.js + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - pattern: $Y.replace(...) + - pattern: $Y.indexOf(...) + - pattern: "function ... (...) {\n ...\n <... $Y.indexOf(...) ...>\n ...\n}\n" + - patterns: + - pattern: $FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: sanitize + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern-inside: "$PATH = require('path');\n...\n" + - pattern-inside: "import $PATH from 'path';\n...\n" + - pattern-either: + - pattern: $PATH.join(...,$SINK,...) + - pattern: $PATH.resolve(...,$SINK,...) + - patterns: + - focus-metavariable: $SINK + - pattern-inside: "import 'path';\n...\n" + - pattern-either: + - pattern: path.join(...,$SINK,...) + - pattern: path.resolve(...,$SINK,...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile + languages: + - javascript + - typescript + message: The application processes user-input, this is passed to res.sendFile which can allow an attacker to + arbitrarily read files on the system through path traversal. It is recommended to perform input validation in + addition to canonicalizing the path. This allows you to validate the path against the intended directory it should + be accessing. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-73: External Control of File Name or Path' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22082 + rule_id: j2UzDx + rv_id: 1263142 + url: + https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + version_id: 7ZTE3X9 + shortlink: https://sg.run/7DJk + source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.$METH($QUERY,...) + - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) + - metavariable-regex: + metavariable: $METH + regex: ^(sendfile|sendFile)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "function ... (...,$REQ: $TYPE, ...) {...}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(string|String) + severity: WARNING +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22083 + rule_id: 10Uo39 + rv_id: 1263143 + url: + https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + version_id: LjTkgle + shortlink: https://sg.run/LYvG + source: + https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + subcategory: + - vuln + technology: + - express + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern-inside: "import $SESSION from 'express-session'\n...\n" + - pattern-inside: "import {..., $SESSION, ...} from 'express-session'\n...\n" + - pattern-inside: "import * as $SESSION from 'express-session'\n...\n" + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: "$SECRET = $VALUE\n...\n$APP.use($SESSION($SECRET))\n" + - pattern: "secret: '$Y'\n" + severity: WARNING +- id: javascript.express.security.audit.express-ssrf.express-ssrf + languages: + - javascript + - typescript + message: 'The following request $REQUEST.$METHOD() was found to be crafted from user-input `$REQ` which can lead to Server-Side + Request Forgery (SSRF) vulnerabilities. It is recommended where possible to not allow user-input to craft the base request, + but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommeneded + to follow OWASP best practices to prevent abuse. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22554 + rule_id: eqU9l2 + rv_id: 1263144 + url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf + version_id: 8KT5rBr + shortlink: https://sg.run/0PNw + source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + taint_unify_mvars: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) + - pattern: $REQ. ... .$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) + - pattern: $REQ.$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...']\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE}...`\n...\n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" + - patterns: + - pattern-either: + - pattern-inside: "$ASSIGN = \"$HTTP\"+ $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ.$VALUE[...]\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ.$VALUE[...] + $...A\n...\n" + - pattern-inside: "$ASSIGN = `$HTTP${$REQ.$VALUE[...]}...`\n...\n" + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQUEST.$METHOD($ASSIGN,...) + - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) + - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) + - patterns: + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) + - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern: $ASSIGN + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, ...) {...} + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,...) =>\n{...}\n" + - pattern-inside: "({ $REQ }: $EXPRESS.Request,...) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: + javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + languages: + - javascript + - typescript + message: The following function call $SER.$FUNC accepts user controlled data which can result in Remote Code Execution + (RCE) through Object Deserialization. It is recommended to use secure data processing alternatives such as + JSON.parse() and Buffer.from(). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22084 + rule_id: 9AUyqj + rv_id: 1263145 + url: + https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + version_id: gETB7nD + shortlink: https://sg.run/8W5j + source: + https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + subcategory: + - vuln + technology: + - express + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + options: + interfile: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$SER = require('$IMPORT')\n...\n" + - pattern-inside: "import $SER from '$IMPORT'\n ...\n" + - pattern-inside: "import * as $SER from '$IMPORT'\n...\n" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: WARNING +- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + languages: + - javascript + - typescript + message: Xml Parser is used inside Request Event. Make sure that unverified user data can not reach the XML Parser, as + it can result in XML External or Internal Entity (XXE) Processing vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.npmjs.com/package/xml2json + semgrep.dev: + rule: + origin: community + r_id: 9274 + rule_id: 8GUjkk + rv_id: 1263146 + url: + https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + version_id: QkTGqgo + shortlink: https://sg.run/x1AA + source: + https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('xml2json');\n...\n" + - pattern-inside: "import 'xml2json';\n...\n" + - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) + - focus-metavariable: $INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.res-render-injection.res-render-injection + languages: + - javascript + - typescript + message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to the loading of other HTML/templating + pages that they may not be authorized to render. An attacker may attempt to use directory traversal techniques e.g. + `../folder/index` to access other HTML pages on the file system. Where possible, do not allow users to define what + should be loaded in $RES.render or use an allow list for the existing application. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - http://expressjs.com/en/4x/api.html#res.render + semgrep.dev: + rule: + origin: community + r_id: 9276 + rule_id: QrUzrq + rv_id: 1263149 + url: + https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection + version_id: PkTR3OY + shortlink: https://sg.run/eLjd + source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authorization + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.render($SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write + languages: + - javascript + - typescript + message: Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and + may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render + safely escaped HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9277 + rule_id: 3qUPA1 + rv_id: 1263150 + url: + https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write + version_id: JdTzxeg + shortlink: https://sg.run/vzGl + source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + options: + interfile: true + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'express-xss-sanitizer';\n...\n" + - pattern-inside: "import * as $S from \"express-xss-sanitizer\";\n...\n" + - pattern-inside: "const { ..., $S, ... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "var { ..., $S, ... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "let { ...,$S,... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "$S = require(\"express-xss-sanitizer\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern: $RES. ... .type('$F'). ... .send(...) + - metavariable-regex: + metavariable: $F + regex: (?!.*text/html) + - patterns: + - pattern-inside: "$X = [...];\n...\n" + - pattern: "if(<... !$X.includes($SOURCE)...>) {\n ...\n return ...\n}\n...\n" + - pattern: $SOURCE + pattern-sinks: + - patterns: + - pattern-inside: function ... (..., $RES,...) {...} + - pattern-either: + - pattern: $RES.write($ARG) + - pattern: $RES.send($ARG) + - pattern-not: $RES. ... .set('...'). ... .send($ARG) + - pattern-not: $RES. ... .type('...'). ... .send($ARG) + - pattern-not-inside: $RES.$METHOD({ ... }) + - focus-metavariable: $ARG + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-not-inside: "function ... ($REQ, $RES) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "$APP.$METHOD(..., function $FUNC($REQ, $RES) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n\ + })\n" + - pattern-not-inside: "function ... ($REQ, $RES, $NEXT) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "function ... ($REQ, $RES) {\n ...\n $RES.set('$TYPE')\n}\n" + - pattern-not-inside: "$APP.$METHOD(..., function $FUNC($REQ, $RES) {\n ...\n $RES.set('$TYPE')\n})\n" + - pattern-not-inside: "function ... ($REQ, $RES, $NEXT) {\n ...\n $RES.set('$TYPE')\n}\n" + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{\n ...\n $RES.$SET('Content-Type', + '$TYPE')\n}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response) => {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{\n ...\n $RES.set('$TYPE')\n\ + }\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: body + severity: WARNING +- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration + languages: + - javascript + - typescript + message: By letting user input control CORS parameters, there is a risk that software does not properly verify that + the source of data or communication is valid. Use literal values for CORS settings. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-346: Origin Validation Error' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS + semgrep.dev: + rule: + origin: community + r_id: 13580 + rule_id: 5rULJQ + rv_id: 1263162 + url: + https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration + version_id: YDTZe8Y + shortlink: https://sg.run/nKXO + source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authentication + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, $X) + - pattern: $RES.header($HEADER, $X) + - pattern: $RES.setHeader($HEADER, $X) + - pattern: "$RES.set({$HEADER: $X}, ...)\n" + - pattern: "$RES.writeHead($STATUS, {$HEADER: $X}, ...)\n" + - focus-metavariable: $X + - metavariable-regex: + metavariable: $HEADER + regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-expat-xxe.express-expat-xxe + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or + Internal Entity (XXE) Processing vulnerabilities. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/astro/node-expat + semgrep.dev: + rule: + origin: community + r_id: 9251 + rule_id: zdUkJl + rv_id: 1263164 + url: https://semgrep.dev/playground/r/o5TbD5l/javascript.express.security.express-expat-xxe.express-expat-xxe + version_id: o5TbD5l + shortlink: https://sg.run/BkXx + source: https://semgrep.dev/r/javascript.express.security.express-expat-xxe.express-expat-xxe + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$XML = require('node-expat')\n...\n" + - pattern-inside: "import $XML from 'node-expat'\n...\n" + - pattern-inside: "import * as $XML from 'node-expat'\n...\n" + - pattern-either: + - pattern-inside: "$PARSER = new $XML.Parser(...);\n...\n" + - pattern-either: + - pattern: $PARSER.parse($QUERY) + - pattern: $PARSER.write($QUERY) + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + languages: + - javascript + - typescript + message: User data from `$REQ` is being compiled into the template, which can lead to a Server Side Template Injection + (SSTI) vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 19226 + rule_id: EwUr9k + rv_id: 1263165 + url: + https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + version_id: zyTb2eD + shortlink: https://sg.run/b49v + source: + https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + source_rule_url: + - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js + subcategory: + - vuln + technology: + - javascript + - typescript + - express + - pug + - jade + - dot + - ejs + - nunjucks + - lodash + - handlbars + - mustache + - hogan.js + - eta + - squirrelly + vulnerability_class: + - Code Injection + mode: taint + options: + interfile: true + pattern-propagators: + - from: $E + pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) + to: $S + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('pug')\n...\n" + - pattern-inside: "import * as $PUG from 'pug'\n...\n" + - pattern-inside: "$PUG = require('jade')\n...\n" + - pattern-inside: "import * as $PUG from 'jade'\n...\n" + - pattern-either: + - pattern: $PUG.compile(...) + - pattern: $PUG.compileClient(...) + - pattern: $PUG.compileClientWithDependenciesTracked(...) + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('dot')\n...\n" + - pattern-inside: "import * as $PUG from 'dot'\n...\n" + - pattern-either: + - pattern: $PUG.template(...) + - pattern: $PUG.compile(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('ejs')\n...\n" + - pattern-inside: "import * as $PUG from 'ejs'\n...\n" + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('nunjucks')\n...\n" + - pattern-inside: "import * as $PUG from 'nunjucks'\n...\n" + - pattern-either: + - pattern: $PUG.renderString(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('lodash')\n...\n" + - pattern-inside: "import * as $PUG from 'lodash'\n...\n" + - pattern-either: + - pattern: $PUG.template(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('mustache')\n...\n" + - pattern-inside: "import * as $PUG from 'mustache'\n...\n" + - pattern-inside: "$PUG = require('eta')\n...\n" + - pattern-inside: "import * as $PUG from 'eta'\n...\n" + - pattern-inside: "$PUG = require('squirrelly')\n...\n" + - pattern-inside: "import * as $PUG from 'squirrelly'\n...\n" + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('hogan.js')\n...\n" + - pattern-inside: "import * as $PUG from 'hogan.js'\n...\n" + - pattern-inside: "$PUG = require('handlebars')\n...\n" + - pattern-inside: "import * as $PUG from 'handlebars'\n...\n" + - pattern-either: + - pattern: $PUG.compile(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9252 + rule_id: pKUOjy + rv_id: 1263166 + url: + https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + version_id: pZT03Q0 + shortlink: https://sg.run/Do1d + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + subcategory: + - audit + technology: + - express + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + patterns: + - pattern-either: + - pattern-inside: "$JWT = require('express-jwt');\n...\n" + - pattern-inside: "import $JWT from 'express-jwt';\n...\n" + - pattern-inside: "import * as $JWT from 'express-jwt';\n...\n" + - pattern-inside: "import { ..., $JWT, ... } from 'express-jwt';\n...\n" + - pattern-either: + - pattern: "$JWT({...,secret: \"$Y\",...},...)\n" + - pattern: "$OPTS = \"$Y\";\n...\n$JWT({...,secret: $OPTS},...);\n" + - focus-metavariable: $Y + severity: WARNING +- id: javascript.express.security.express-phantom-injection.express-phantom-injection + languages: + - javascript + - typescript + message: If unverified user data can reach the `phantom` methods it can result in Server-Side Request Forgery + vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://phantomjs.org/page-automation.html + semgrep.dev: + rule: + origin: community + r_id: 9253 + rule_id: 2ZUbx3 + rv_id: 1263167 + url: + https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection + version_id: 2KTv26p + shortlink: https://sg.run/W8BL + source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('phantom');\n...\n" + - pattern-inside: "import 'phantom';\n...\n" + - pattern-either: + - pattern: $PAGE.open($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.openUrl($SINK,...) + - pattern: $PAGE.evaluateJavaScript($SINK,...) + - pattern: $PAGE.property("content",$SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + languages: + - javascript + - typescript + message: If unverified user data can reach the `puppeteer` methods it can result in Server-Side Request Forgery + vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://pptr.dev/api/puppeteer.page + semgrep.dev: + rule: + origin: community + r_id: 9254 + rule_id: X5U8Nz + rv_id: 1263168 + url: + https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + version_id: X0TzyJY + shortlink: https://sg.run/0QJB + source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('puppeteer');\n...\n" + - pattern-inside: "import 'puppeteer';\n...\n" + - pattern-either: + - pattern: $PAGE.goto($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.evaluate($SINK,...) + - pattern: $PAGE.evaluate($CODE,$SINK,...) + - pattern: $PAGE.evaluateHandle($SINK,...) + - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `sandbox`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9255 + rule_id: j2UvXB + rv_id: 1263169 + url: + https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + version_id: jQTn59D + shortlink: https://sg.run/KlwL + source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$SANDBOX = require('sandbox');\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$S = new $SANDBOX(...);\n...\n" + - pattern: "$S.run(...)\n" + - pattern: "new $SANDBOX($OPTS).run(...)\n" + - pattern: new $SANDBOX().run(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-vm-injection.express-vm-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `$VM`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 12821 + rule_id: DbUKPX + rv_id: 1263170 + url: + https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection + version_id: 1QTypXQ + shortlink: https://sg.run/jkqJ + source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$VM = require('vm');\n...\n" + - pattern-either: + - pattern: "$VM.runInContext(...)\n" + - pattern: "$VM.runInNewContext(...)\n" + - pattern: "$VM.compileFunction(...)\n" + - pattern: "$VM.runInThisContext(...)\n" + - pattern: new $VM.Script(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-vm2-injection.express-vm2-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `vm2`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 12822 + rule_id: WAUPXJ + rv_id: 1263171 + url: + https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection + version_id: 9lT4bnX + shortlink: https://sg.run/1GWv + source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "require('vm2')\n...\n" + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$VM = new VM(...)\n...\n" + - pattern-inside: "$VM = new NodeVM(...)\n...\n" + - pattern: "$VM.run(...)\n" + - pattern: "new VM(...).run(...)\n" + - pattern: "new NodeVM(...).run(...)\n" + - pattern: "new VMScript(...)\n" + - pattern: "new VM(...)\n" + - pattern: new NodeVM(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or + Internal Entity (XXE) Processing vulnerabilities + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.npmjs.com/package/xml2json + semgrep.dev: + rule: + origin: community + r_id: 9264 + rule_id: x8Uneb + rv_id: 1263174 + url: + https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + version_id: bZT534J + shortlink: https://sg.run/XBD4 + source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('xml2json');\n...\n" + - pattern-inside: "import 'xml2json';\n...\n" + - pattern: $EXPAT.toJson($SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: javascript.express.security.injection.raw-html-format.raw-html-format + languages: + - javascript + - typescript + message: User data flows into the host portion of this manually-constructed HTML. This can introduce a + Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. Consider using a sanitization + library such as DOMPurify to sanitize the HTML within. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 14691 + rule_id: 5rUL0X + rv_id: 1263175 + url: + https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format + version_id: NdTzyQv + shortlink: https://sg.run/5DO3 + source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" + $EXPR' + - pattern: '"$HTMLSTR".concat(...)' + - pattern: util.format($HTMLSTR, ...) + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - patterns: + - pattern: "`...`\n" + - pattern-regex: ".*<\\w+.*\n" + requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) + pattern-sources: + - label: EXPRESS + patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - label: EXPRESSTS + patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - by-side-effect: true + label: CLEAN + patterns: + - pattern-either: + - pattern: $A($SOURCE) + - pattern: $SANITIZE. ... .$A($SOURCE) + - pattern: $A. ... .$SANITIZE($SOURCE) + - focus-metavariable: $SOURCE + - metavariable-regex: + metavariable: $A + regex: (?i)(.*valid|.*sanitiz) + severity: WARNING +- id: javascript.express.security.require-request.require-request + languages: + - javascript + - typescript + message: If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on + the server. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it + semgrep.dev: + rule: + origin: community + r_id: 9265 + rule_id: OrU3WK + rv_id: 1263177 + url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request + version_id: w8TRo0d + shortlink: https://sg.run/jRbl + source: https://semgrep.dev/r/javascript.express.security.require-request.require-request + source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authorization + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: require($SINK) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + languages: + - javascript + - typescript + message: By letting user input control `X-Frame-Options` header, there is a risk that software does not properly + verify whether or not a browser should be allowed to render a page in an `iframe`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + semgrep.dev: + rule: + origin: community + r_id: 13581 + rule_id: GdUrLy + rv_id: 1263178 + url: + https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + version_id: xyTjz3D + shortlink: https://sg.run/EvjA + source: + https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Other + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, ...) + - pattern: $RES.header($HEADER, ...) + - pattern: $RES.setHeader($HEADER, ...) + - pattern: "$RES.set({$HEADER: ...}, ...)\n" + - pattern: "$RES.writeHead($STATUS, {$HEADER: ...}, ...)\n" + - metavariable-regex: + metavariable: $HEADER + regex: .*(X-Frame-Options|x-frame-options).* + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: + javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + languages: + - js + message: Found an initialization of the Intercom Messenger that identifies a User, but does not specify a `user_hash`. + This configuration allows users to impersonate one another. See the Intercom Identity Verification docs for more + context https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-287: Improper Authentication' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://www.intercom.com/help/en/articles/183-set-up-identity-verification-for-web-and-mobile + semgrep.dev: + rule: + origin: community + r_id: 60237 + rule_id: QrU96W + rv_id: 945842 + url: + https://semgrep.dev/playground/r/nWTpzDk/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + version_id: nWTpzDk + shortlink: https://sg.run/Eb5w + source: + https://semgrep.dev/r/javascript.intercom.security.audit.intercom-settings-user-identifier-without-user-hash.intercom-settings-user-identifier-without-user-hash + subcategory: + - audit + technology: + - intercom + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: "window.intercomSettings = {..., email: $EMAIL, ...};\n" + - pattern: "window.intercomSettings = {..., user_id: $USER_ID, ...};\n" + - pattern: "Intercom('boot', {..., email: $EMAIL, ...});\n" + - pattern: "Intercom('boot', {..., user_id: $USER_ID, ...});\n" + - pattern: "$VAR = {..., email: $EMAIL, ...};\n...\nIntercom('boot', $VAR);\n" + - pattern: "$VAR = {..., user_id: $EMAIL, ...};\n...\nIntercom('boot', $VAR);\n" + - pattern-not: "window.intercomSettings = {..., user_hash: $USER_HASH, ...};\n" + - pattern-not: "Intercom('boot', {..., user_hash: $USER_HASH, ...});\n" + - pattern-not: "$VAR = {..., user_hash: $USER_HASH, ...};\n...\nIntercom('boot', $VAR);\n" + severity: WARNING +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9293 + rule_id: JDUyRl + rv_id: 1263182 + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + version_id: d6TyxbX + shortlink: https://sg.run/Ro1g + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jose + - jwt + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + symbolic_propagation: true + patterns: + - pattern-inside: "$JOSE = require(\"jose\");\n...\n" + - pattern-either: + - pattern-inside: "var {JWT} = $JOSE;\n...\n" + - pattern-inside: "var {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWK, JWT} = $JOSE;\n...\n" + - pattern-either: + - pattern: "JWT.verify($P, \"...\", ...);\n" + - pattern: "JWT.sign($P, \"...\", ...);\n" + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: "$JWT.sign($P, JWK.asKey(\"...\"), ...);\n" + severity: WARNING +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9294 + rule_id: 5rUOGN + rv_id: 1263183 + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + version_id: ZRTKAyb + shortlink: https://sg.run/AvRL + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jose + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nvar $T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\n$T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nJWT.verify($P, JWK.None,...);\n" + severity: ERROR +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9300 + rule_id: WAUon7 + rv_id: 1263189 + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + version_id: gETB75D + shortlink: https://sg.run/4xN9 + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jwt + - javascript + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$JWT = require(\"jsonwebtoken\")\n...\n" + - pattern-inside: "import $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import * as $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import {...,$JWT,...} from \"jsonwebtoken\"\n...\n" + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,$VALUE,...);\n" + - pattern-inside: "$JWT.verify($DATA,$VALUE,...);\n" + - focus-metavariable: $VALUE + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,\"...\",...);\n" + - pattern-inside: "$JWT.verify($DATA,\"...\",...);\n" + severity: WARNING +- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9301 + rule_id: 0oU53g + rv_id: 1263190 + url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + version_id: QkTGqQo + shortlink: https://sg.run/PJXv + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "$JWT = require(\"jsonwebtoken\");\n...\n" + - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) + severity: ERROR +- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + languages: + - javascript + - typescript + message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise + the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Set 'verify' + to `true` before using the token. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-287: Improper Authentication' + - 'CWE-345: Insufficient Verification of Data Authenticity' + - 'CWE-347: Improper Verification of Cryptographic Signature' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A07:2021 - Identification and Authentication Failures + - A02:2025 - Security Misconfiguration + - A07:2025 - Authentication Failures + references: + - https://www.npmjs.com/package/jwt-simple + - https://cwe.mitre.org/data/definitions/287 + - https://cwe.mitre.org/data/definitions/345 + - https://cwe.mitre.org/data/definitions/347 + semgrep.dev: + rule: + origin: community + r_id: 120561 + rule_id: r6UyNLy + rv_id: 1263191 + url: + https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + version_id: 3ZT4Xxv + shortlink: https://sg.run/zdjod + source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + subcategory: + - vuln + technology: + - jwt-simple + - jwt + vulnerability_class: + - Cryptographic Issues + - Improper Authentication + patterns: + - pattern-inside: "$JWT = require('jwt-simple');\n...\n" + - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) + - metavariable-pattern: + metavariable: $NOVERIFY + patterns: + - pattern-either: + - pattern: "true\n" + - pattern: "\"...\"\n" + severity: ERROR +- id: javascript.lang.security.audit.code-string-concat.code-string-concat + languages: + - javascript + - typescript + message: Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can + lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever + possible. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval + - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback + - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ + - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html + semgrep.dev: + rule: + origin: community + r_id: 13023 + rule_id: DbUKEz + rv_id: 1263192 + url: + https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat + version_id: 44TEjYX + shortlink: https://sg.run/96Yk + source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat + subcategory: + - vuln + technology: + - node.js + - Express + - Next.js + vulnerability_class: + - Code Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: "eval(...)\n" + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "import { ...,$IMPORT,... } from 'next/router'\n...\n" + - pattern-inside: "import $IMPORT from 'next/router';\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$ROUTER = $IMPORT()\n...\n" + - pattern-either: + - pattern-inside: "const { ...,$PROPS,... } = $ROUTER.query\n...\n" + - pattern-inside: "var { ...,$PROPS,... } = $ROUTER.query\n...\n" + - pattern-inside: "let { ...,$PROPS,... } = $ROUTER.query\n...\n" + - focus-metavariable: $PROPS + - patterns: + - pattern-inside: "$ROUTER = $IMPORT()\n...\n" + - pattern: "$ROUTER.query.$VALUE \n" + - patterns: + - pattern: $IMPORT().query.$VALUE + severity: ERROR +- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$REQ` object. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared + statements. An example of parameterized queries like so: `knex.raw('SELECT $1 from table', [userinput])` can help prevent + SQLi." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 18257 + rule_id: d8UKLD + rv_id: 1263205 + url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + version_id: l4TJRey + shortlink: https://sg.run/l9eE + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + subcategory: + - vuln + technology: + - express + - nodejs + - knex + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $KNEX.fromRaw($QUERY, ...) + - pattern-inside: $KNEX.whereRaw($QUERY, ...) + - pattern-inside: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: "require('knex')\n...\n" + - pattern-inside: "import 'knex'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: WARNING +- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + languages: + - javascript + - typescript + message: Detected use of dynamic execution of JavaScript which may come from user-input, which can lead to + Cross-Site-Scripting (XSS). Where possible avoid including user-input in functions which dynamically execute + user-input. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval! + semgrep.dev: + rule: + origin: community + r_id: 9315 + rule_id: yyUngo + rv_id: 1263214 + url: + https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + version_id: WrTqKkJ + shortlink: https://sg.run/6nwK + source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + source-rule-url: + https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js + subcategory: + - vuln + technology: + - javascript + vulnerability_class: + - Code Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: location.href = $FUNC(...) + - pattern: location.hash = $FUNC(...) + - pattern: location.search = $FUNC(...) + - pattern: $WINDOW. ... .location.href = $FUNC(...) + - pattern: $WINDOW. ... .location.hash = $FUNC(...) + - pattern: $WINDOW. ... .location.search = $FUNC(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval(<... $SINK ...>) + - pattern: window.eval(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>)(...) + - pattern: setTimeout(<... $SINK ...>,...) + - pattern: setInterval(<... $SINK ...>,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "$PROP = new URLSearchParams($WINDOW. ... .location.search).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams(location.search).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams(location.hash.substring(1)).get('...')\n ...\n" + - focus-metavariable: $PROP + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.search)\n ...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.search)\n ...\n" + - pattern-inside: "$PROPS = new\nURLSearchParams($WINDOW. ... .location.hash.substring(1))\n ...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.hash.substring(1))\n...\n" + - pattern: $PROPS.get('...') + - focus-metavariable: $PROPS + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + severity: WARNING +- id: javascript.node-crypto.security.aead-no-final.aead-no-final + languages: + - javascript + - typescript + message: The 'final' call of a Decipher object checks the authentication tag in a mode for authenticated encryption. + Failing to call 'final' will invalidate all integrity guarantees of the released ciphertext. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 146569 + rule_id: 2ZUz884 + rv_id: 1263222 + url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final + version_id: zyTb2X0 + shortlink: https://sg.run/r6EEA + source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final + subcategory: + - vuln + technology: + - node-crypto + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)\n...\n$DECIPHER.update(...)\n" + - pattern-not-inside: "$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)\n...\n$DECIPHER.final(...)\n" + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ + severity: ERROR +- id: javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + languages: + - javascript + - typescript + message: The deprecated functions 'createCipher' and 'createDecipher' generate the same initialization vector every + time. For counter modes such as CTR, GCM, or CCM this leads to break of both confidentiality and integrity, if the + key is used more than once. Other modes are still affected in their strength, though they're not completely broken. + Use 'createCipheriv' or 'createDecipheriv' instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-1204: Generation of Weak Initialization Vector (IV)' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + references: + - https://nodejs.org/api/crypto.html#cryptocreatecipheralgorithm-password-options + - https://nodejs.org/api/crypto.html#cryptocreatedecipheralgorithm-password-options + semgrep.dev: + rule: + origin: community + r_id: 146570 + rule_id: X5UQRR7 + rv_id: 945898 + url: + https://semgrep.dev/playground/r/ZRT3510/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + version_id: ZRT3510 + shortlink: https://sg.run/bw33r + source: https://semgrep.dev/r/javascript.node-crypto.security.create-de-cipher-no-iv.create-de-cipher-no-iv + subcategory: + - vuln + technology: + - node-crypto + vulnerability_class: + - Other + patterns: + - pattern-either: + - pattern: "$CRYPTO.createCipher(...)\n" + - pattern: "$CRYPTO.createDecipher(...)\n" + severity: ERROR +- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + languages: + - javascript + - typescript + message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode of operation is missing an expected + authentication tag length. If the expected authentication tag length is not specified or otherwise checked, the + application might be tricked into verifying a shorter-than-expected authentication tag. This can be abused by an + attacker to spoof ciphertexts or recover the implicit authentication key of GCM, allowing arbitrary forgeries. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ + - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 146571 + rule_id: j2UgPP3 + rv_id: 1263223 + url: + https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + version_id: pZT03qd + shortlink: https://sg.run/NbGG1 + source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + subcategory: + - vuln + technology: + - node-crypto + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$CRYPTO.createDecipheriv('$ALGO', $KEY, $IV)\n" + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm)$ + severity: ERROR +- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9333 + rule_id: QrUzq6 + rv_id: 1263225 + url: + https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + version_id: X0TzyoE + shortlink: https://sg.run/vz70 + source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + subcategory: + - vuln + technology: + - jwt + - nodejs + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$F = require(\"$I\").Strategy\n...\n" + - pattern-inside: "$F = require(\"$I\")\n...\n" + - pattern-inside: "import { $STRAT as $F } from '$I'\n...\n" + - pattern-inside: "import $F from '$I'\n...\n" + - metavariable-regex: + metavariable: $I + regex: (passport-.*) + - pattern-inside: "new $F($VALUE,...)\n" + - focus-metavariable: $VALUE + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: "{..., clientSecret: \"...\", ...}\n" + - pattern: "{..., secretOrKey: \"...\", ...}\n" + - pattern: "{..., consumerSecret: \"...\", ...}\n" + - patterns: + - pattern-inside: "$OBJ = {}\n...\n" + - pattern-either: + - pattern: "$OBJ.clientSecret = \"...\"\n" + - pattern: "$OBJ.secretOrKey = \"...\"\n" + - pattern: "$OBJ.consumerSecret = \"...\"\n" + - pattern: $OBJ + - patterns: + - pattern-inside: "$SECRET = '...'\n...\n" + - pattern-either: + - pattern: "{..., clientSecret: $SECRET, ...}\n" + - pattern: "{..., secretOrKey: $SECRET, ...}\n" + - pattern: "{..., consumerSecret: $SECRET, ...}\n" + - patterns: + - pattern-inside: "$SECRET = '...'\n...\n" + - pattern-either: + - pattern-inside: "$VALUE = {..., clientSecret: $SECRET, ...}\n...\n" + - pattern-inside: "$VALUE = {..., secretOrKey: $SECRET, ...}\n...\n" + - pattern-inside: "$VALUE = {..., consumerSecret: $SECRET, ...}\n...\n" + - pattern: $VALUE + severity: WARNING +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + languages: + - javascript + - typescript + message: Detected a sequelize statement that is tainted by user-input. This could lead to SQL injection if the + variable is user-controlled and is not properly sanitized. In order to prevent SQL injection, it is recommended to + use parameterized queries or prepared statements. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + semgrep.dev: + rule: + origin: community + r_id: 22085 + rule_id: yyU0GX + rv_id: 1263241 + url: + https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + version_id: nWT2Llx + shortlink: https://sg.run/gjoe + source: + https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: problem-based-packs.insecure-transport.js-node.bypass-tls-verification.bypass-tls-verification + languages: + - javascript + - typescript + message: Checks for setting the environment variable NODE_TLS_REJECT_UNAUTHORIZED to 0, which disables TLS + verification. This should only be used for debugging purposes. Setting the option rejectUnauthorized to false + bypasses verification against the list of trusted CAs, which also leads to insecure transport. These options lead to + vulnerability to MTM attacks, and should not be used. + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A03:2017 - Sensitive Data Exposure + references: + - https://nodejs.org/api/https.html#https_https_request_options_callback + - https://stackoverflow.com/questions/20433287/node-js-request-cert-has-expired#answer-29397100 + semgrep.dev: + rule: + origin: community + r_id: 9423 + rule_id: OrU3Y6 + rv_id: 946067 + url: + https://semgrep.dev/playground/r/JdTDybO/problem-based-packs.insecure-transport.js-node.bypass-tls-verification.bypass-tls-verification + version_id: JdTDybO + shortlink: https://sg.run/9oxr + source: + https://semgrep.dev/r/problem-based-packs.insecure-transport.js-node.bypass-tls-verification.bypass-tls-verification + subcategory: + - vuln + technology: + - node.js + vulnerability: Insecure Transport + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: "process.env[\"NODE_TLS_REJECT_UNAUTHORIZED\"] = 0;\n" + - pattern: "{rejectUnauthorized:false}\n" + severity: WARNING +- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + languages: + - typescript + message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes + from user-provided input. If you have to use `$TRUST`, ensure it does not come from user-input or use the + appropriate prevention mechanism e.g. input validation or sanitization depending on the context. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://angular.io/api/platform-browser/DomSanitizer + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9755 + rule_id: oqUzgA + rv_id: 1263902 + url: + https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + version_id: 5PTo1zk + shortlink: https://sg.run/KWxP + source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + subcategory: + - vuln + technology: + - angular + - browser + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern: sanitizer.sanitize(...) + - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.$TRUST($Y) + - focus-metavariable: $Y + - pattern-not: "$X.$TRUST(`...`)\n" + - pattern-not: "$X.$TRUST(\"...\")\n" + - metavariable-regex: + metavariable: $TRUST + regex: + (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X: string, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X: string, ...) { ... }\n" + - focus-metavariable: $X + severity: WARNING +- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + languages: + - typescript + message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" to the bucket + props for Bucket construct $X' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + semgrep.dev: + rule: + origin: community + r_id: 15276 + rule_id: bwU8qz + rv_id: 1263903 + url: + https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + version_id: GxTkeRx + shortlink: https://sg.run/eowX + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3'\n...\n" + - pattern: const $X = new Bucket(...) + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...})\n" + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3'\n...\n" + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...})\n" + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...})\n" + severity: ERROR +- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + languages: + - ts + message: Bucket $X is not set to enforce encryption-in-transit, if not explictly setting this on the bucket policy - + the property "enforceSSL" should be set to true + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + semgrep.dev: + rule: + origin: community + r_id: 15277 + rule_id: NbUN8B + rv_id: 1263904 + url: + https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + version_id: RGT0Llg + shortlink: https://sg.run/vqBX + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3';\n...\n" + - pattern: const $X = new Bucket(...) + - pattern-not: "const $X = new Bucket(..., {enforceSSL: true}, ...)\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3';\n...\n" + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: "const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...})\n" + severity: ERROR +- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + languages: + - ts + message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" or "encryption: $Y.QueueEncryption.KMS_MANAGED" + to the queue props to enable encryption at rest for the queue.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html + semgrep.dev: + rule: + origin: community + r_id: 15278 + rule_id: kxUwqO + rv_id: 1263905 + url: + https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + version_id: A8Tgd2W + shortlink: https://sg.run/d23P + source: + https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import {Queue} from '@aws-cdk/aws-sqs'\n...\n" + - pattern: const $X = new Queue(...) + - pattern-not: "const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-sqs'\n...\n" + - pattern: const $X = new $Y.Queue(...) + - pattern-not: "const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...})\n" + severity: WARNING +- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + languages: + - ts + message: Using the GrantPublicAccess method on bucket contruct $X will make the objects in the bucket world + accessible. Verify if this is intentional. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html + semgrep.dev: + rule: + origin: community + r_id: 15279 + rule_id: wdUjZK + rv_id: 1263906 + url: + https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + version_id: BjTkZA7 + shortlink: https://sg.run/Z4p7 + source: + https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Improper Authentication + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3'\n...\n" + - pattern: "const $X = new Bucket(...)\n...\n$X.grantPublicAccess(...)\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3'\n...\n" + - pattern: "const $X = new $Y.Bucket(...)\n...\n$X.grantPublicAccess(...)\n" + severity: WARNING +- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + languages: + - ts + message: CodeBuild Project $X is set to have a public URL. This will make the build results, logs, artifacts + publically accessible, including builds prior to the project being public. Ensure this is acceptable for the + project. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html + semgrep.dev: + rule: + origin: community + r_id: 15280 + rule_id: x8UxXZ + rv_id: 1263907 + url: + https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + version_id: DkTRbj1 + shortlink: https://sg.run/nK7G + source: + https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Improper Authentication + pattern-either: + - patterns: + - pattern-inside: "import {Project} from '@aws-cdk/aws-codebuild'\n...\n" + - pattern: "const $X = new Project(..., {..., badge: true, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-codebuild'\n...\n" + - pattern: "const $X = new $Y.Project(..., {..., badge: true, ...})\n" + severity: WARNING +- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + languages: + - typescript + - javascript + message: Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to + cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use + dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + semgrep.dev: + rule: + origin: community + r_id: 9769 + rule_id: x8UWvK + rv_id: 1263912 + url: + https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + version_id: l4TJR0v + shortlink: https://sg.run/rAx6 + source: + https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern-either: + - pattern: "{...,dangerouslySetInnerHTML: {__html: $X},...}\n" + - pattern: "<$Y ... dangerouslySetInnerHTML={{__html: $X}} />\n" + - pattern-not: "<$Y ... dangerouslySetInnerHTML={{__html: \"...\"}} />\n" + - pattern-not: "{...,dangerouslySetInnerHTML:{__html: \"...\"},...}\n" + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: "{...}\n" + - pattern-not: "<... {__html: \"...\"} ...>\n" + - pattern-not: "<... {__html: `...`} ...>\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-not-inside: "$F. ... .$SANITIZEUNC(...)\n" + severity: WARNING +- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + languages: + - typescript + - javascript + message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting + (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization + library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln + - https://developer.mozilla.org/en-US/docs/Web/API/Document/write + - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML + semgrep.dev: + rule: + origin: community + r_id: 9781 + rule_id: QrU68w + rv_id: 1263916 + url: + https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + version_id: GxTkeRl + shortlink: https://sg.run/E5x8 + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" + - pattern: "window.document. ... .$HTML('...',$SINK) \n" + - pattern: "document.$HTML($SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (writeln|write) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: "$PROP. ... .$HTML('...',$SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (insertAdjacentHTML) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + severity: WARNING +- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + languages: + - typescript + - javascript + message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting + (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization + library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + semgrep.dev: + rule: + origin: community + r_id: 9782 + rule_id: 3qUBl4 + rv_id: 1263917 + url: + https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + version_id: RGT0Lln + shortlink: https://sg.run/70Zv + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$BODY = $REACT.useRef(...)\n...\n" + - pattern-inside: "$BODY = useRef(...)\n...\n" + - pattern-inside: "$BODY = findDOMNode(...)\n...\n" + - pattern-inside: "$BODY = createRef(...)\n...\n" + - pattern-inside: "$BODY = $REACT.findDOMNode(...)\n...\n" + - pattern-inside: "$BODY = $REACT.createRef(...)\n...\n" + - pattern-either: + - pattern: "$BODY. ... .$HTML = $SINK \n" + - pattern: "$BODY.$HTML = $SINK \n" + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: ReactDOM.findDOMNode(...).$HTML = $SINK + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + severity: WARNING +- id: typescript.react.security.react-insecure-request.react-insecure-request + languages: + - typescript + - javascript + message: Unencrypted request over HTTP detected. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.npmjs.com/package/axios + semgrep.dev: + rule: + origin: community + r_id: 9766 + rule_id: NbUA3O + rv_id: 1263918 + url: + https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request + version_id: A8Tgd2p + shortlink: https://sg.run/1n0b + source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request + subcategory: + - vuln + technology: + - react + vulnerability: Insecure Transport + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "import $AXIOS from 'axios';\n...\n$AXIOS.$METHOD(...)\n" + - pattern-inside: "$AXIOS = require('axios');\n...\n$AXIOS.$METHOD(...)\n" + - pattern: $AXIOS.$VERB("$URL",...) + - metavariable-regex: + metavariable: $VERB + regex: ^(get|post|delete|head|patch|put|options) + - patterns: + - pattern-either: + - pattern-inside: "import $AXIOS from 'axios';\n...\n$AXIOS(...)\n" + - pattern-inside: "$AXIOS = require('axios');\n...\n$AXIOS(...)\n" + - pattern-either: + - pattern: '$AXIOS({url: "$URL"}, ...)' + - pattern: "$OPTS = {url: \"$URL\"}\n...\n$AXIOS($OPTS, ...)\n" + - pattern: fetch("$URL", ...) + - metavariable-regex: + metavariable: $URL + regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) + severity: ERROR diff --git a/.semgrep/registry/owasp-top-ten.yaml b/.semgrep/registry/owasp-top-ten.yaml new file mode 100644 index 0000000..a4aad93 --- /dev/null +++ b/.semgrep/registry/owasp-top-ten.yaml @@ -0,0 +1,33829 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/owasp-top-ten +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: bash.curl.security.curl-eval.curl-eval + languages: + - bash + message: Data is being eval'd from a `curl` command. An attacker with control of the server in the `curl` command + could inject malicious code into the `eval`, resulting in a system comrpomise. Avoid eval'ing untrusted data if you + can. If you must do this, consider checking the SHA sum of the content returned by the server to verify its + integrity. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 14554 + rule_id: KxU7Rq + rv_id: 1262601 + url: https://semgrep.dev/playground/r/JdTzxL2/bash.curl.security.curl-eval.curl-eval + version_id: JdTzxL2 + shortlink: https://sg.run/0yqJ + source: https://semgrep.dev/r/bash.curl.security.curl-eval.curl-eval + subcategory: + - vuln + technology: + - bash + - curl + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - pattern: eval ... + pattern-sources: + - pattern: "$(curl ...)\n" + - pattern: "`curl ...`\n" + severity: WARNING +- id: clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + languages: + - clojure + message: DOCTYPE declarations are enabled for javax.xml.parsers.SAXParserFactory. Without prohibiting external entity + declarations, this is vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only + prohibit external entities declarations. This can be done by setting the features + "http://xml.org/sax/features/external-general-entities" and + "http://xml.org/sax/features/external-parameter-entities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://xerces.apache.org/xerces2-j/features.html + semgrep.dev: + rule: + origin: community + r_id: 71533 + rule_id: bwU3Gj + rv_id: 1262608 + url: + https://semgrep.dev/playground/r/WrTqKyD/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + version_id: WrTqKyD + shortlink: https://sg.run/v7An + source: https://semgrep.dev/r/clojure.lang.security.documentbuilderfactory-xxe.documentbuilderfactory-xxe + source-rule-url: + https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/xxe-clojure-xml/xxe-clojure-xml.yml + subcategory: + - vuln + technology: + - clojure + - xml + vulnerability_class: + - XML Injection + patterns: + - pattern-inside: "(ns ... (:require [clojure.xml :as ...]))\n...\n" + - pattern-either: + - pattern-inside: "(def ... ... ( ... ))\n" + - pattern-inside: "(defn ... ... ( ... ))\n" + - pattern-either: + - pattern: (clojure.xml/parse $INPUT) + - patterns: + - pattern-inside: "(doto (javax.xml.parsers.SAXParserFactory/newInstance) ...)\n" + - pattern: (.setFeature "http://apache.org/xml/features/disallow-doctype-decl" false) + - pattern-not-inside: "(doto (javax.xml.parsers.SAXParserFactory/newInstance)\n ...\n (.setFeature \"http://xml.org/sax/features/external-general-entities\"\ + \ false)\n ...\n (.setFeature \"http://xml.org/sax/features/external-parameter-entities\" false)\n ...)\n" + - pattern-not-inside: "(doto (javax.xml.parsers.SAXParserFactory/newInstance)\n ...\n (.setFeature \"http://xml.org/sax/features/external-parameter-entities\"\ + \ false)\n ...\n (.setFeature \"http://xml.org/sax/features/external-general-entities\" false)\n ...)\n" + severity: ERROR +- id: clojure.lang.security.use-of-md5.use-of-md5 + languages: + - clojure + message: MD5 hash algorithm detected. This is not collision resistant and leads to easily-cracked password hashes. + Replace with current recommended hashing algorithms. + metadata: + author: Gabriel Marquet + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 52195 + rule_id: nJU1ep + rv_id: 1262609 + url: https://semgrep.dev/playground/r/0bTKz2B/clojure.lang.security.use-of-md5.use-of-md5 + version_id: 0bTKz2B + shortlink: https://sg.run/BgPx + source: https://semgrep.dev/r/clojure.lang.security.use-of-md5.use-of-md5 + source-rule-url: https://github.com/clj-holmes/clj-holmes-rules/blob/main/security/weak-hash-function-md5.yml + subcategory: + - vuln + technology: + - clojure + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: (MessageDigest/getInstance "MD5") + - pattern: (MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance "MD5") + - pattern: (java.security.MessageDigest/getInstance MessageDigestAlgorithms/MD5) + - pattern: (java.security.MessageDigest/getInstance org.apache.commons.codec.digest.MessageDigestAlgorithms/MD5) + severity: WARNING +- id: clojure.lang.security.use-of-sha1.use-of-sha1 + languages: + - clojure + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other + hash function applications. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-328: Use of Weak Hash' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 71534 + rule_id: NbUy12 + rv_id: 1262610 + url: https://semgrep.dev/playground/r/K3TKk7E/clojure.lang.security.use-of-sha1.use-of-sha1 + version_id: K3TKk7E + shortlink: https://sg.run/dvwX + source: https://semgrep.dev/r/clojure.lang.security.use-of-sha1.use-of-sha1 + subcategory: + - vuln + technology: + - clojure + vulnerability_class: + - Cryptographic Issues + - Insecure Hashing Algorithm + patterns: + - pattern-either: + - pattern: (MessageDigest/getInstance $ALGO) + - pattern: (java.security.MessageDigest/getInstance $ALGO) + - metavariable-regex: + metavariable: $ALGO + regex: (((org\.apache\.commons\.codec\.digest\.)?MessageDigestAlgorithms/)?"?(SHA-1|SHA1)"?) + severity: WARNING +- id: csharp.dotnet.security.audit.ldap-injection.ldap-injection + languages: + - csharp + message: LDAP queries are constructed dynamically on user-controlled input. This vulnerability in code could lead to + an arbitrary LDAP query execution. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection/ + - https://cwe.mitre.org/data/definitions/90 + - https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#safe-c-sharp-net-tba-example + semgrep.dev: + rule: + origin: community + r_id: 27692 + rule_id: 2ZUv3R + rv_id: 1262612 + url: https://semgrep.dev/playground/r/l4TJR8G/csharp.dotnet.security.audit.ldap-injection.ldap-injection + version_id: l4TJR8G + shortlink: https://sg.run/GJ9z + source: https://semgrep.dev/r/csharp.dotnet.security.audit.ldap-injection.ldap-injection + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - LDAP Injection + mode: taint + options: + taint_unify_mvars: true + pattern-sanitizers: + - pattern-either: + - pattern: Regex.Replace($INPUT, ...) + - pattern: $ENCODER.LdapFilterEncode($INPUT) + - pattern: $ENCODER.LdapDistinguishedNameEncode($INPUT) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $S.Filter = ... + $INPUT + ... + - pattern: $S.Filter = String.Format(...,$INPUT) + - pattern: $S.Filter = String.Concat(...,$INPUT) + pattern-sources: + - patterns: + - focus-metavariable: $INPUT + - pattern-inside: $T $M(...,$INPUT,...) {...} + severity: ERROR +- id: csharp.dotnet.security.audit.mass-assignment.mass-assignment + languages: + - csharp + message: Mass assignment or Autobinding vulnerability in code allows an attacker to execute over-posting attacks, + which could create a new parameter in the binding request and manipulate the underlying object in the application. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/915.html + - https://github.com/OWASP/API-Security/blob/master/2019/en/src/0xa6-mass-assignment.md + semgrep.dev: + rule: + origin: community + r_id: 26838 + rule_id: x8Up5B + rv_id: 1262613 + url: https://semgrep.dev/playground/r/YDTZeD9/csharp.dotnet.security.audit.mass-assignment.mass-assignment + version_id: YDTZeD9 + shortlink: https://sg.run/7B3e + source: https://semgrep.dev/r/csharp.dotnet.security.audit.mass-assignment.mass-assignment + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Mass Assignment + mode: taint + pattern-sinks: + - pattern: View(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: "public IActionResult $METHOD(..., $TYPE $ARG, ...){\n ...\n}\n" + - pattern: "public ActionResult $METHOD(..., $TYPE $ARG, ...){\n ...\n}\n" + - pattern-inside: "using Microsoft.AspNetCore.Mvc;\n...\n" + - pattern-not: "public IActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){\n ...\n}\n" + - pattern-not: "public ActionResult $METHOD(..., [Bind(...)] $TYPE $ARG, ...){\n ...\n}\n" + - focus-metavariable: $ARG + severity: WARNING +- id: csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + languages: + - csharp + message: Anonymous access shouldn't be allowed unless explicit by design. Access control checks are missing and + potentially can be bypassed. This finding violates the principle of least privilege or deny by default, where access + should only be permitted for a specific set of roles or conforms to a custom policy or users. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-862: Missing Authorization' + cwe2021-top25: true + cwe2022-top25: true + cwe2023-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + - https://cwe.mitre.org/data/definitions/862.html + - https://docs.microsoft.com/en-us/aspnet/core/security/authorization/simple?view=aspnetcore-7.0 + semgrep.dev: + rule: + origin: community + r_id: 26335 + rule_id: eqU32Y + rv_id: 1262615 + url: + https://semgrep.dev/playground/r/o5TbD41/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + version_id: o5TbD41 + shortlink: https://sg.run/Z8GA + source: + https://semgrep.dev/r/csharp.dotnet.security.audit.missing-or-broken-authorization.missing-or-broken-authorization + subcategory: + - vuln + technology: + - .net + - mvc + vulnerability_class: + - Improper Authorization + patterns: + - pattern: "public class $CLASS : Controller {\n ...\n}\n" + - pattern-inside: "using Microsoft.AspNetCore.Mvc;\n...\n" + - pattern-not: "[AllowAnonymous]\npublic class $CLASS : Controller {\n ...\n}\n" + - pattern-not: "[Authorize]\npublic class $CLASS : Controller {\n ...\n}\n" + - pattern-not: "[Authorize(Roles = ...)]\npublic class $CLASS : Controller {\n ...\n}\n" + - pattern-not: "[Authorize(Policy = ...)]\npublic class $CLASS : Controller {\n ...\n}\n" + severity: INFO +- id: csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + languages: + - csharp + message: An open directory listing is potentially exposed, potentially revealing sensitive information to attackers. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cwe.mitre.org/data/definitions/548.html + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration/ + - https://docs.microsoft.com/en-us/aspnet/core/fundamentals/static-files?view=aspnetcore-7.0#directory-browsing + semgrep.dev: + rule: + origin: community + r_id: 26336 + rule_id: v8U8Ab + rv_id: 1262616 + url: + https://semgrep.dev/playground/r/zyTb2Y2/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + version_id: zyTb2Y2 + shortlink: https://sg.run/n0y1 + source: https://semgrep.dev/r/csharp.dotnet.security.audit.open-directory-listing.open-directory-listing + subcategory: + - vuln + technology: + - .net + - mvc + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - pattern: (IApplicationBuilder $APP).UseDirectoryBrowser(...); + - pattern: $BUILDER.Services.AddDirectoryBrowser(...); + - pattern-inside: "public void Configure(...) {\n ...\n}\n" + severity: INFO +- id: csharp.dotnet.security.audit.xpath-injection.xpath-injection + languages: + - csharp + message: XPath queries are constructed dynamically on user-controlled input. This vulnerability in code could lead to + an XPath Injection exploitation. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection/ + - https://cwe.mitre.org/data/definitions/643.html + semgrep.dev: + rule: + origin: community + r_id: 27400 + rule_id: x8Uj2k + rv_id: 1262618 + url: https://semgrep.dev/playground/r/2KTv2Pq/csharp.dotnet.security.audit.xpath-injection.xpath-injection + version_id: 2KTv2Pq + shortlink: https://sg.run/4KP7 + source: https://semgrep.dev/r/csharp.dotnet.security.audit.xpath-injection.xpath-injection + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - XPath Injection + mode: taint + pattern-sinks: + - pattern-either: + - pattern: XPathExpression $EXPR = $NAV.Compile("..." + $INPUT + "..."); + - pattern: var $EXPR = $NAV.Compile("..." + $INPUT + "..."); + - pattern: XPathNodeIterator $NODE = $NAV.Select("..." + $INPUT + "..."); + - pattern: var $NODE = $NAV.Select("..." + $INPUT + "..."); + - pattern: Object $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); + - pattern: var $OBJ = $NAV.Evaluate("..." + $INPUT + "..."); + pattern-sources: + - pattern-either: + - pattern: $T $M($INPUT,...) {...} + - pattern: "$T $M(...) {\n ...\n string $INPUT;\n}\n" + severity: ERROR +- id: csharp.dotnet.security.razor-template-injection.razor-template-injection + languages: + - csharp + message: User-controllable string passed to Razor.Parse. This leads directly to code execution in the context of the + process. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/ + semgrep.dev: + rule: + origin: community + r_id: 18216 + rule_id: EwUr68 + rv_id: 1262621 + url: + https://semgrep.dev/playground/r/1QTypdj/csharp.dotnet.security.razor-template-injection.razor-template-injection + version_id: 1QTypdj + shortlink: https://sg.run/oyj0 + source: https://semgrep.dev/r/csharp.dotnet.security.razor-template-injection.razor-template-injection + subcategory: + - vuln + technology: + - .net + - razor + - asp + vulnerability_class: + - Code Injection + mode: taint + pattern-sanitizers: + - not_conflicting: true + pattern: $F(...) + pattern-sinks: + - pattern: "Razor.Parse(...)\n" + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: "public ActionResult $METHOD(..., string $ARG,...){...}\n" + severity: WARNING +- id: csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + languages: + - csharp + message: Usage of deprecated cipher algorithm detected. Use Aes or ChaCha20Poly1305 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.des?view=net-6.0#remarks + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rc2?view=net-6.0#remarks + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aes?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + semgrep.dev: + rule: + origin: community + r_id: 36772 + rule_id: WAUJr0 + rv_id: 1262622 + url: + https://semgrep.dev/playground/r/9lT4bRK/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + version_id: 9lT4bRK + shortlink: https://sg.run/k8Qo + source: https://semgrep.dev/r/csharp.dotnet.security.use_deprecated_cipher_algorithm.use_deprecated_cipher_algorithm + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: $KEYTYPE.Create(...); + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: DES + - pattern: RC2 + severity: ERROR +- id: csharp.dotnet.security.use_ecb_mode.use_ecb_mode + languages: + - csharp + message: Usage of the insecure ECB mode detected. You should use an authenticated encryption mode instead, which is + implemented by the classes AesGcm or ChaCha20Poly1305. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.chacha20poly1305?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0 + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.ciphermode?view=net-6.0 + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + semgrep.dev: + rule: + origin: community + r_id: 36773 + rule_id: 0oUqWP + rv_id: 1262623 + url: https://semgrep.dev/playground/r/yeTxpPw/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + version_id: yeTxpPw + shortlink: https://sg.run/wj9n + source: https://semgrep.dev/r/csharp.dotnet.security.use_ecb_mode.use_ecb_mode + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: ($KEYTYPE $KEY).EncryptEcb(...); + - pattern: ($KEYTYPE $KEY).DecryptEcb(...); + - pattern: ($KEYTYPE $KEY).Mode = CipherMode.ECB; + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 + severity: WARNING +- id: csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + languages: + - csharp + message: You are using an insecure random number generator (RNG) to create a cryptographic key. System.Random must + never be used for cryptographic purposes. Use System.Security.Cryptography.RandomNumberGenerator instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-us/dotnet/api/system.random?view=net-6.0#remarks + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.randomnumbergenerator?view=net-6.0 + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm?view=net-6.0#constructors + - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.symmetricalgorithm.key?view=net-6.0#system-security-cryptography-symmetricalgorithm-key + semgrep.dev: + rule: + origin: community + r_id: 36774 + rule_id: KxU3Nq + rv_id: 1262624 + url: + https://semgrep.dev/playground/r/rxTAK2O/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + version_id: rxTAK2O + shortlink: https://sg.run/xjrA + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rng_for_keygeneration.use_weak_rng_for_keygeneration + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - pattern-either: + - patterns: + - pattern: ($KEYTYPE $CIPHER).Key = $SINK; + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $KEYTYPE + pattern-either: + - pattern: SymmetricAlgorithm + - pattern: Aes + - pattern: Rijndael + - pattern: DES + - pattern: TripleDES + - pattern: RC2 + - pattern: new AesGcm(...) + - pattern: new AesCcm(...) + - pattern: new ChaCha20Poly1305(...) + pattern-sources: + - patterns: + - pattern-inside: (System.Random $RNG).NextBytes($KEY); ... + - pattern: $KEY + severity: ERROR +- id: csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + languages: + - csharp + message: You are using the outdated PKCS#1 v1.5 encryption padding for your RSA key. Use the OAEP padding instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsapkcs1keyexchangedeformatter + - https://learn.microsoft.com/en-gb/dotnet/api/system.security.cryptography.rsaoaepkeyexchangedeformatter + semgrep.dev: + rule: + origin: community + r_id: 35492 + rule_id: QrU2G5 + rv_id: 1262625 + url: + https://semgrep.dev/playground/r/bZT53zb/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + version_id: bZT53zb + shortlink: https://sg.run/GoJ1 + source: https://semgrep.dev/r/csharp.dotnet.security.use_weak_rsa_encryption_padding.use_weak_rsa_encryption_padding + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: (RSAPKCS1KeyExchangeFormatter $FORMATER).CreateKeyExchange(...); + - pattern: (RSAPKCS1KeyExchangeDeformatter $DEFORMATER).DecryptKeyExchange(...); + severity: WARNING +- fix: "true\n" + id: + csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + languages: + - csharp + message: The TokenValidationParameters.$LIFETIME is set to $FALSE, this means the JWT tokens lifetime is not + validated. This can lead to an JWT token being used after it has expired, which has security implications. It is + recommended to validate the JWT lifetime to ensure only valid tokens are used. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-613: Insufficient Session Expiration' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://cwe.mitre.org/data/definitions/613.html + - https://docs.microsoft.com/en-us/dotnet/api/microsoft.identitymodel.tokens.tokenvalidationparameters?view=azure-dotnet + semgrep.dev: + rule: + origin: community + r_id: 28955 + rule_id: bwU5kK + rv_id: 1262628 + url: + https://semgrep.dev/playground/r/w8TRolJ/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + version_id: w8TRolJ + shortlink: https://sg.run/KA0d + source: + https://semgrep.dev/r/csharp.lang.security.ad.jwt-tokenvalidationparameters-no-expiry-validation.jwt-tokenvalidationparameters-no-expiry-validation + subcategory: + - audit + technology: + - csharp + vulnerability_class: + - Improper Authorization + patterns: + - pattern-either: + - patterns: + - pattern: $LIFETIME = $FALSE + - pattern-inside: new TokenValidationParameters {...} + - patterns: + - pattern: "(TokenValidationParameters $OPTS). ... .$LIFETIME = $FALSE\n" + - metavariable-regex: + metavariable: $LIFETIME + regex: (RequireExpirationTime|ValidateLifetime) + - metavariable-regex: + metavariable: $FALSE + regex: (false) + - focus-metavariable: $FALSE + severity: WARNING +- fix: RequireSignedTokens = true + id: csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + languages: + - csharp + message: Accepting unsigned security tokens as valid security tokens allows an attacker to remove its signature and + potentially forge an identity. As a fix, set RequireSignedTokens to be true. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-347: Improper Verification of Cryptographic Signature' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + - https://cwe.mitre.org/data/definitions/347 + semgrep.dev: + rule: + origin: community + r_id: 26718 + rule_id: KxUGLw + rv_id: 1262631 + url: + https://semgrep.dev/playground/r/e1Tyjrz/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + version_id: e1Tyjrz + shortlink: https://sg.run/pqzN + source: https://semgrep.dev/r/csharp.lang.security.cryptography.unsigned-security-token.unsigned-security-token + subcategory: + - vuln + technology: + - csharp + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: RequireSignedTokens = false + - pattern-inside: "new TokenValidationParameters {\n ...\n}\n" + severity: ERROR +- id: csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + languages: + - csharp + message: Validating certificates based on subject name is bad practice. Use the X509Certificate2.Verify() method + instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.identitymodel.tokens.issuernameregistry?view=netframework-4.8 + semgrep.dev: + rule: + origin: community + r_id: 18220 + rule_id: gxUy01 + rv_id: 1262629 + url: + https://semgrep.dev/playground/r/xyTjzGW/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + version_id: xyTjzGW + shortlink: https://sg.run/XZ6B + source: + https://semgrep.dev/r/csharp.lang.security.cryptography.x509-subject-name-validation.X509-subject-name-validation + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Improper Authentication + patterns: + - pattern-inside: "using System.IdentityModel.Tokens;\n...\n" + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "X509SecurityToken $TOK = $RHS;\n...\n" + - pattern-inside: "$T $M(..., X509SecurityToken $TOK, ...) {\n ...\n}\n" + - metavariable-pattern: + metavariable: $RHS + pattern-either: + - pattern: $T as X509SecurityToken + - pattern: new X509SecurityToken(...) + - patterns: + - pattern-either: + - pattern-inside: "X509Certificate2 $CERT = new X509Certificate2(...);\n...\n" + - pattern-inside: "$T $M(..., X509Certificate2 $CERT, ...) {\n ...\n}\n" + - pattern-inside: "foreach (X509Certificate2 $CERT in $COLLECTION) {\n ...\n}\n" + - patterns: + - pattern-either: + - pattern: String.Equals($NAME, "...") + - pattern: String.Equals("...", $NAME) + - pattern: $NAME.Equals("...") + - pattern: $NAME == "..." + - pattern: $NAME != "..." + - pattern: "\"...\" == $NAME\n" + - pattern: "\"...\" != $NAME\n" + - metavariable-pattern: + metavariable: $NAME + pattern-either: + - pattern: $TOK.Certificate.SubjectName.Name + - pattern: $CERT.SubjectName.Name + - pattern: $CERT.GetNameInfo(...) + severity: WARNING +- id: csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + languages: + - csharp + message: String argument $A is used to read or write data from a file via Path.Combine without direct sanitization via + Path.GetFileName. If the path is user-supplied data this can lead to path traversal. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.praetorian.com/blog/pathcombine-security-issues-in-aspnet-applications/ + - https://docs.microsoft.com/en-us/dotnet/api/system.io.path.combine?view=net-6.0#remarks + semgrep.dev: + rule: + origin: community + r_id: 18222 + rule_id: 3qU3bE + rv_id: 1262632 + url: + https://semgrep.dev/playground/r/vdT0644/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + version_id: vdT0644 + shortlink: https://sg.run/1RvG + source: https://semgrep.dev/r/csharp.lang.security.filesystem.unsafe-path-combine.unsafe-path-combine + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - pattern: "Path.GetFileName(...)\n" + - patterns: + - pattern-inside: "$X = Path.GetFileName(...);\n...\n" + - pattern: $X + - patterns: + - pattern: $X + - pattern-inside: "if(<... Path.GetFileName($X) != $X ...>){\n ...\n throw new $EXCEPTION(...);\n}\n...\n" + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern: "File.$METHOD($X,...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: (?i)^(read|write) + pattern-sources: + - patterns: + - pattern: $A + - pattern-inside: "Path.Combine(...,$A,...)\n" + - pattern-inside: "public $TYPE $M(...,$A,...){...}\n" + - pattern-not-inside: "<... Path.GetFileName($A) != $A ...>\n" + severity: WARNING +- id: csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + languages: + - C# + message: The top level wildcard bindings $PREFIX leaves your application open to security vulnerabilities and give + attackers more control over where traffic is routed. If you must use wildcards, consider using subdomain wildcard + binding. For example, you can use "*.asdf.gov" if you own all of "asdf.gov". + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.net.httplistener?view=net-6.0 + semgrep.dev: + rule: + origin: community + r_id: 18223 + rule_id: 4bUQ81 + rv_id: 1262633 + url: + https://semgrep.dev/playground/r/d6Tyx4K/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + version_id: d6Tyx4K + shortlink: https://sg.run/9LJr + source: + https://semgrep.dev/r/csharp.lang.security.http.http-listener-wildcard-bindings.http-listener-wildcard-bindings + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "using System.Net;\n...\n" + - pattern: $LISTENER.Prefixes.Add("$PREFIX") + - metavariable-regex: + metavariable: $PREFIX + regex: (http|https)://(\*|\+)(.[a-zA-Z]{2,})?:[0-9]+ + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + languages: + - C# + message: The BinaryFormatter type is dangerous and is not recommended for data processing. Applications should stop + using BinaryFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. + BinaryFormatter is insecure and can't be made secure + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-security-guide + semgrep.dev: + rule: + origin: community + r_id: 11135 + rule_id: bwUOjK + rv_id: 1262635 + url: + https://semgrep.dev/playground/r/nWT2LGp/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + version_id: nWT2LGp + shortlink: https://sg.run/ZeXW + source: + https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.binary-formatter.insecure-binaryformatter-deserialization + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "using System.Runtime.Serialization.Formatters.Binary;\n...\n" + - pattern: "new BinaryFormatter();\n" + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + languages: + - C# + message: The FsPickler is dangerous and is not recommended for data processing. Default configuration tend to insecure + deserialization vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://mbraceproject.github.io/FsPickler/tutorial.html#Disabling-Subtype-Resolution + semgrep.dev: + rule: + origin: community + r_id: 11137 + rule_id: kxURnR + rv_id: 1262638 + url: + https://semgrep.dev/playground/r/LjTkgPk/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + version_id: LjTkgPk + shortlink: https://sg.run/E5e5 + source: + https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.fs-pickler.insecure-fspickler-deserialization + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "using MBrace.FsPickler.Json;\n...\n" + - pattern: "FsPickler.CreateJsonSerializer();\n" + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + languages: + - C# + message: The LosFormatter type is dangerous and is not recommended for data processing. Applications should stop using + LosFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. LosFormatter + is insecure and can't be made secure + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.web.ui.losformatter?view=netframework-4.8 + semgrep.dev: + rule: + origin: community + r_id: 11138 + rule_id: wdU87G + rv_id: 1262641 + url: + https://semgrep.dev/playground/r/QkTGqnA/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + version_id: QkTGqnA + shortlink: https://sg.run/70pG + source: + https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.los-formatter.insecure-losformatter-deserialization + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "using System.Web.UI;\n...\n" + - pattern: "new LosFormatter();\n" + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + languages: + - C# + message: The NetDataContractSerializer type is dangerous and is not recommended for data processing. Applications + should stop using NetDataContractSerializer as soon as possible, even if they believe the data they're processing to + be trustworthy. NetDataContractSerializer is insecure and can't be made secure + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.netdatacontractserializer?view=netframework-4.8#security + semgrep.dev: + rule: + origin: community + r_id: 11139 + rule_id: x8UW7x + rv_id: 1262642 + url: + https://semgrep.dev/playground/r/3ZT4X6b/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + version_id: 3ZT4X6b + shortlink: https://sg.run/L0AX + source: + https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.net-data-contract.insecure-netdatacontract-deserialization + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "using System.Runtime.Serialization;\n...\n" + - pattern: "new NetDataContractSerializer();\n" + severity: WARNING +- id: csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + languages: + - C# + message: The SoapFormatter type is dangerous and is not recommended for data processing. Applications should stop + using SoapFormatter as soon as possible, even if they believe the data they're processing to be trustworthy. + SoapFormatter is insecure and can't be made secure + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.microsoft.com/en-us/dotnet/api/system.runtime.serialization.formatters.soap.soapformatter?view=netframework-4.8#remarks + semgrep.dev: + rule: + origin: community + r_id: 11141 + rule_id: eqUvND + rv_id: 1262644 + url: + https://semgrep.dev/playground/r/PkTR30n/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + version_id: PkTR30n + shortlink: https://sg.run/gJnR + source: + https://semgrep.dev/r/csharp.lang.security.insecure-deserialization.soap-formatter.insecure-soapformatter-deserialization + subcategory: + - vuln + technology: + - .net + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "using System.Runtime.Serialization.Formatters.Soap;\n...\n" + - pattern: "new SoapFormatter();\n" + severity: WARNING +- id: + csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + languages: + - C# + message: 'Specifying the regex timeout leaves the system vulnerable to a regex-based Denial of Service (DoS) attack. Consider + setting the timeout to a short amount of time like 2 or 3 seconds. If you are sure you need an infinite timeout, double + check that your context meets the conditions outlined in the "Notes to Callers" section at the bottom of this page: https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A01:2017 - Injection + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.infinitematchtimeout + - https://docs.microsoft.com/en-us/dotnet/api/system.text.regularexpressions.regex.-ctor?view=net-6.0 + semgrep.dev: + rule: + origin: community + r_id: 18227 + rule_id: GdUDBP + rv_id: 945224 + url: + https://semgrep.dev/playground/r/yeT0nDq/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + version_id: yeT0nDq + shortlink: https://sg.run/NgRy + source: + https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos-infinite-timeout.regular-expression-dos-infinite-timeout + subcategory: + - audit + technology: + - .net + vulnerability_class: + - Denial-of-Service (DoS) + patterns: + - pattern-inside: "using System.Text.RegularExpressions;\n...\n" + - pattern-either: + - pattern: new Regex(..., TimeSpan.InfiniteMatchTimeout) + - patterns: + - pattern: new Regex(..., TimeSpan.FromSeconds($TIME)) + - metavariable-comparison: + comparison: $TIME > 5 + metavariable: $TIME + - pattern: new Regex(..., TimeSpan.FromMinutes(...)) + - pattern: new Regex(..., TimeSpan.FromHours(...)) + severity: WARNING +- id: csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + languages: + - C# + message: When using `System.Text.RegularExpressions` to process untrusted input, pass a timeout. A malicious user can + provide input to `RegularExpressions` that abuses the backtracking behaviour of this regular expression engine. This + will lead to excessive CPU usage, causing a Denial-of-Service attack + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A01:2017 - Injection + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + - https://docs.microsoft.com/en-us/dotnet/standard/base-types/regular-expressions#regular-expression-examples + semgrep.dev: + rule: + origin: community + r_id: 12005 + rule_id: 4bU2gd + rv_id: 945225 + url: + https://semgrep.dev/playground/r/rxT6rjl/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + version_id: rxT6rjl + shortlink: https://sg.run/RPyY + source: + https://semgrep.dev/r/csharp.lang.security.regular-expression-dos.regular-expression-dos.regular-expression-dos + subcategory: + - audit + technology: + - .net + vulnerability_class: + - Denial-of-Service (DoS) + patterns: + - pattern-inside: "using System.Text.RegularExpressions;\n...\n" + - pattern-either: + - pattern: "public $T $F($X)\n{\n Regex $Y = new Regex($P);\n ...\n $Y.Match($X);\n}\n" + - pattern: "public $T $F($X)\n{\n Regex $Y = new Regex($P, $O);\n ...\n $Y.Match($X);\n}\n" + - pattern: "public $T $F($X)\n{\n ... Regex.Match($X, $P);\n}\n" + - pattern: "public $T $F($X)\n{\n ... Regex.Match($X, $P, $O);\n}\n" + severity: WARNING +- id: csharp.lang.security.sqli.csharp-sqli.csharp-sqli + languages: + - csharp + message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL + statement are not properly sanitized. Use a prepared statements instead. You can obtain a PreparedStatement using + 'SqlCommand' and 'SqlParameter'. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 15078 + rule_id: x8UxeP + rv_id: 1262648 + url: https://semgrep.dev/playground/r/RGT0LqW/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + version_id: RGT0LqW + shortlink: https://sg.run/d2Xd + source: https://semgrep.dev/r/csharp.lang.security.sqli.csharp-sqli.csharp-sqli + subcategory: + - audit + technology: + - csharp + vulnerability_class: + - SQL Injection + mode: taint + pattern-propagators: + - from: $X + pattern: (StringBuilder $B).$ANY(...,(string $X),...) + to: $B + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - pattern: "$CMD.Parameters.Add(...)\n" + - pattern: "$CMD.Parameters.AddRange(...)\n" + - pattern: "$CMD.Parameters.AddWithValue(...)\n" + - pattern: "$CMD.Parameters[$IDX].Value = ...\n" + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: "new $PATTERN($CMD,...)\n" + - focus-metavariable: $CMD + - patterns: + - pattern: "$CMD.$PATTERN = $VALUE;\n" + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $PATTERN + regex: ^(SqlCommand|CommandText|OleDbCommand|OdbcCommand|OracleCommand)$ + pattern-sources: + - patterns: + - pattern: "(string $X)\n" + - pattern-not: "\"...\"\n" + severity: ERROR +- id: csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + languages: + - csharp + message: Stacktrace information is displayed in a non-Development environment. Accidentally disclosing sensitive stack + trace information in a production environment aids an attacker in reconnaissance and information gathering. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-209: Generation of Error Message Containing Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A06:2017 - Security Misconfiguration + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://cwe.mitre.org/data/definitions/209.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + semgrep.dev: + rule: + origin: community + r_id: 26720 + rule_id: lBU6Dv + rv_id: 1262653 + url: https://semgrep.dev/playground/r/0bTKzrB/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + version_id: 0bTKzrB + shortlink: https://sg.run/XvkA + source: https://semgrep.dev/r/csharp.lang.security.stacktrace-disclosure.stacktrace-disclosure + subcategory: + - audit + technology: + - csharp + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: $APP.UseDeveloperExceptionPage(...); + - pattern-not-inside: "if ($ENV.IsDevelopment(...)) {\n ...\n}\n" + - pattern-not-inside: "if ($ENV.EnvironmentName == \"Development\") {\n ...\n}\n" + severity: WARNING +- id: csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + languages: + - csharp + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public + method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied + with user-controllable data. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + semgrep.dev: + rule: + origin: community + r_id: 18228 + rule_id: ReUK9k + rv_id: 1262654 + url: + https://semgrep.dev/playground/r/K3TKk5E/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + version_id: K3TKk5E + shortlink: https://sg.run/k98P + source: + https://semgrep.dev/r/csharp.lang.security.xxe.xmldocument-unsafe-parser-override.xmldocument-unsafe-parser-override + subcategory: + - vuln + technology: + - .net + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: "$XMLDOCUMENT.$METHOD(...)\n" + - pattern-inside: "XmlDocument $XMLDOCUMENT = new XmlDocument(...);\n...\n$XMLDOCUMENT.XmlResolver = new XmlUrlResolver(...);\n\ + ... \n" + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: "public $T $M(...,string $ARG,...){...}\n" + severity: WARNING +- id: csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + languages: + - csharp + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public + method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied + with user-controllable data. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + semgrep.dev: + rule: + origin: community + r_id: 18229 + rule_id: AbU3pX + rv_id: 1262655 + url: + https://semgrep.dev/playground/r/qkTR7WD/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + version_id: qkTR7WD + shortlink: https://sg.run/wXjA + source: + https://semgrep.dev/r/csharp.lang.security.xxe.xmlreadersettings-unsafe-parser-override.xmlreadersettings-unsafe-parser-override + subcategory: + - vuln + technology: + - .net + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: "XmlReader $READER = XmlReader.Create(...,$RS,...);\n" + - pattern-inside: "XmlReaderSettings $RS = new XmlReaderSettings();\n...\n$RS.DtdProcessing = DtdProcessing.Parse;\n...\ + \ \n" + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: "public $T $M(...,string $ARG,...){...}\n" + severity: WARNING +- id: csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + languages: + - csharp + message: XmlReaderSettings found with DtdProcessing.Parse on an XmlReader handling a string argument from a public + method. Enabling Document Type Definition (DTD) parsing may cause XML External Entity (XXE) injection if supplied + with user-controllable data. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.jardinesoftware.net/2016/05/26/xxe-and-net/ + - https://docs.microsoft.com/en-us/dotnet/api/system.xml.xmldocument.xmlresolver?view=net-6.0#remarks + semgrep.dev: + rule: + origin: community + r_id: 18230 + rule_id: BYUevk + rv_id: 1262656 + url: + https://semgrep.dev/playground/r/l4TJRWG/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + version_id: l4TJRWG + shortlink: https://sg.run/xXjL + source: https://semgrep.dev/r/csharp.lang.security.xxe.xmltextreader-unsafe-defaults.xmltextreader-unsafe-defaults + subcategory: + - vuln + technology: + - .net + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: "$READER.$METHOD(...)\n" + - pattern-not-inside: "$READER.DtdProcessing = DtdProcessing.Prohibit;\n...\n" + - pattern-inside: "XmlTextReader $READER = new XmlTextReader(...);\n...\n" + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: "public $T $M(...,string $ARG,...){...}\n" + severity: WARNING +- id: dockerfile.security.last-user-is-root.last-user-is-root + languages: + - dockerfile + message: The last user in the container is 'root'. This is a security hazard because if an attacker gains control of + the container they will have root access. Switch back to another user after running commands as 'root'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-269: Improper Privilege Management' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://github.com/hadolint/hadolint/wiki/DL3002 + semgrep.dev: + rule: + origin: community + r_id: 20147 + rule_id: ReU2n5 + rv_id: 1262658 + url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root + version_id: 6xT29Eg + shortlink: https://sg.run/5Z43 + source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root + source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 + subcategory: + - audit + technology: + - dockerfile + vulnerability_class: + - Improper Authorization + patterns: + - pattern: USER root + - pattern-not-inside: + patterns: + - pattern: "USER root\n...\nUSER $X\n" + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: root + severity: ERROR +- fix: "USER non-root\nENTRYPOINT $...VARS\n" + id: dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + languages: + - dockerfile + message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an + attacker can control a process running as root, they may have control over the container. Ensure that the last USER + in a Dockerfile is a USER other than 'root'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-269: Improper Privilege Management' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 47272 + rule_id: ReUW9E + rv_id: 1262659 + url: + https://semgrep.dev/playground/r/o5TbD21/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + version_id: o5TbD21 + shortlink: https://sg.run/k281 + source: https://semgrep.dev/r/dockerfile.security.missing-user-entrypoint.missing-user-entrypoint + subcategory: + - audit + technology: + - dockerfile + vulnerability_class: + - Improper Authorization + patterns: + - pattern: "ENTRYPOINT $...VARS\n" + - pattern-not-inside: "USER $USER\n...\n" + severity: ERROR +- fix: "USER non-root\nCMD $...VARS\n" + id: dockerfile.security.missing-user.missing-user + languages: + - dockerfile + message: By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an + attacker can control a process running as root, they may have control over the container. Ensure that the last USER + in a Dockerfile is a USER other than 'root'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 20148 + rule_id: AbUN06 + rv_id: 1262660 + url: https://semgrep.dev/playground/r/zyTb2n2/dockerfile.security.missing-user.missing-user + version_id: zyTb2n2 + shortlink: https://sg.run/Gbvn + source: https://semgrep.dev/r/dockerfile.security.missing-user.missing-user + subcategory: + - audit + technology: + - dockerfile + vulnerability_class: + - Improper Authorization + patterns: + - pattern: "CMD $...VARS\n" + - pattern-not-inside: "USER $USER\n...\n" + - pattern-not-inside: "HEALTHCHECK ... CMD ...\n" + severity: ERROR +- id: dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + languages: + - dockerfile + message: Avoid using sudo in Dockerfiles. Running processes as a non-root user can help reduce the potential impact + of configuration errors and security vulnerabilities. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/250.html + - https://docs.docker.com/develop/develop-images/dockerfile_best-practices/#user + semgrep.dev: + rule: + origin: community + r_id: 66384 + rule_id: kxUlx1 + rv_id: 1262661 + url: https://semgrep.dev/playground/r/pZT03zY/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + version_id: pZT03zY + shortlink: https://sg.run/80Q7 + source: https://semgrep.dev/r/dockerfile.security.no-sudo-in-dockerfile.no-sudo-in-dockerfile + subcategory: + - audit + technology: + - dockerfile + vulnerability_class: + - Improper Authorization + patterns: + - pattern: "RUN sudo ...\n" + severity: WARNING +- id: generic.ci.security.bash-reverse-shell.bash_reverse_shell + languages: + - generic + message: Semgrep found a bash reverse shell + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 16200 + rule_id: gxUJrJ + rv_id: 1262664 + url: https://semgrep.dev/playground/r/jQTn5QE/generic.ci.security.bash-reverse-shell.bash_reverse_shell + version_id: jQTn5QE + shortlink: https://sg.run/4l9l + source: https://semgrep.dev/r/generic.ci.security.bash-reverse-shell.bash_reverse_shell + subcategory: + - audit + technology: + - ci + vulnerability_class: + - Code Injection + pattern-either: + - pattern: "sh -i >& /dev/udp/.../... 0>&1\n" + - pattern: "<...>/dev/tcp/.../...; sh <&... >&... 2>&\n" + - pattern: "<...>/dev/tcp/.../...; cat <&... | while read line; do $line 2>&... >&...;done\n" + - pattern: "sh -i ...<...> /dev/tcp/.../... ...<&... 1>&... 2>&\n" + severity: ERROR +- id: generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + languages: + - generic + message: The host for this proxy URL is dynamically determined. This can be dangerous if the host can be injected by + an attacker because it may forcibly alter destination of the proxy. Consider hardcoding acceptable destinations and + retrieving them with 'map' or something similar. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://nginx.org/en/docs/http/ngx_http_map_module.html + semgrep.dev: + rule: + origin: community + r_id: 9036 + rule_id: GdU7yl + rv_id: 1262671 + url: https://semgrep.dev/playground/r/kbTzG2j/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + version_id: kbTzG2j + shortlink: https://sg.run/ndpb + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-host.dynamic-proxy-host + source-rule-url: https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Server-Side Request Forgery (SSRF) + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + pattern-either: + - pattern: proxy_pass $SCHEME://$$HOST ...; + - pattern: proxy_pass $$SCHEME://$$HOST ...; + severity: WARNING +- id: generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + languages: + - generic + message: The protocol scheme for this proxy is dynamically determined. This can be dangerous if the scheme can be + injected by an attacker because it may forcibly alter the connection scheme. Consider hardcoding a scheme for this + proxy. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-16: CWE CATEGORY: Configuration' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/ssrf.md + semgrep.dev: + rule: + origin: community + r_id: 9037 + rule_id: ReUg7n + rv_id: 1262672 + url: https://semgrep.dev/playground/r/w8TRoAJ/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + version_id: w8TRoAJ + shortlink: https://sg.run/EkAo + source: https://semgrep.dev/r/generic.nginx.security.dynamic-proxy-scheme.dynamic-proxy-scheme + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Other + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + pattern: proxy_pass $$SCHEME:// ...; + severity: WARNING +- id: generic.nginx.security.header-injection.header-injection + languages: + - generic + message: "The $$VARIABLE path parameter is added as a header in the response. This could allow an attacker to inject a newline + and add a new header into the response. This is called HTTP response splitting. To fix, do not allow whitespace in the + path parameter: '[^\\s]+'." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/httpsplitting.md + - https://owasp.org/www-community/attacks/HTTP_Response_Splitting + semgrep.dev: + rule: + origin: community + r_id: 9038 + rule_id: AbUz8p + rv_id: 1262673 + url: https://semgrep.dev/playground/r/xyTjzNW/generic.nginx.security.header-injection.header-injection + version_id: xyTjzNW + shortlink: https://sg.run/7oj4 + source: https://semgrep.dev/r/generic.nginx.security.header-injection.header-injection + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Improper Validation + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + pattern: "location ... <$VARIABLE> ... {\n ...\n add_header ... $$VARIABLE\n ...\n}\n" + severity: ERROR +- id: generic.nginx.security.insecure-ssl-version.insecure-ssl-version + languages: + - generic + message: Detected use of an insecure SSL version. Secure SSL versions are TLSv1.2 and TLS1.3; older versions are known + to be broken and are susceptible to attacks. Prefer use of TLSv1.2 or later. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://www.acunetix.com/blog/articles/tls-ssl-cipher-hardening/ + semgrep.dev: + rule: + origin: community + r_id: 9041 + rule_id: WAUo9k + rv_id: 1262676 + url: https://semgrep.dev/playground/r/vdT06O4/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + version_id: vdT06O4 + shortlink: https://sg.run/gLKy + source: https://semgrep.dev/r/generic.nginx.security.insecure-ssl-version.insecure-ssl-version + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Cryptographic Issues + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + patterns: + - pattern-not: ssl_protocols TLSv1.2 TLSv1.3; + - pattern-not: ssl_protocols TLSv1.3 TLSv1.2; + - pattern-not: ssl_protocols TLSv1.2; + - pattern-not: ssl_protocols TLSv1.3; + - pattern: ssl_protocols ...; + severity: WARNING +- id: generic.nginx.security.missing-ssl-version.missing-ssl-version + languages: + - generic + message: This server configuration is missing the 'ssl_protocols' directive. By default, this server will use + 'ssl_protocols TLSv1 TLSv1.1 TLSv1.2', and versions older than TLSv1.2 are known to be broken. Explicitly specify + 'ssl_protocols TLSv1.2 TLSv1.3' to use secure TLS versions. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.acunetix.com/blog/web-security-zone/hardening-nginx/ + - https://nginx.org/en/docs/http/configuring_https_servers.html + semgrep.dev: + rule: + origin: community + r_id: 9043 + rule_id: KxUbeA + rv_id: 1262678 + url: https://semgrep.dev/playground/r/ZRTKAle/generic.nginx.security.missing-ssl-version.missing-ssl-version + version_id: ZRTKAle + shortlink: https://sg.run/3xzl + source: https://semgrep.dev/r/generic.nginx.security.missing-ssl-version.missing-ssl-version + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Cryptographic Issues + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + patterns: + - pattern: server { ... listen $PORT ssl; ... } + - pattern-not-inside: server { ... ssl_protocols ... } + severity: WARNING +- id: generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + languages: + - generic + message: 'Conditions for Nginx H2C smuggling identified. H2C smuggling allows upgrading HTTP/1.1 connections to lesser-known + HTTP/2 over cleartext (h2c) connections which can allow a bypass of reverse proxy access controls, and lead to long-lived, + unrestricted HTTP traffic directly to back-end servers. To mitigate: WebSocket support required: Allow only the value + websocket for HTTP/1.1 upgrade headers (e.g., Upgrade: websocket). WebSocket support not required: Do not forward Upgrade + headers.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://labs.bishopfox.com/tech-blog/h2c-smuggling-request-smuggling-via-http/2-cleartext-h2c + semgrep.dev: + rule: + origin: community + r_id: 10562 + rule_id: 6JUq0Z + rv_id: 1262679 + url: + https://semgrep.dev/playground/r/nWT2Lyp/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + version_id: nWT2Lyp + shortlink: https://sg.run/ploZ + source: https://semgrep.dev/r/generic.nginx.security.possible-h2c-smuggling.possible-nginx-h2c-smuggling + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Improper Validation + paths: + include: + - '*.conf' + - '*.vhost' + - '**/sites-available/*' + - '**/sites-enabled/*' + patterns: + - pattern-either: + - pattern: "proxy_http_version 1.1 ...;\n...\nproxy_set_header Upgrade ...;\n...\nproxy_set_header Connection ...;\n" + - pattern: "proxy_set_header Upgrade ...;\n...\nproxy_set_header Connection ...;\n...\nproxy_http_version 1.1 ...;\n" + - pattern: "proxy_set_header Upgrade ...;\n...\nproxy_http_version 1.1 ...;\n...\nproxy_set_header Connection ...;\n" + - pattern-inside: "location ... {\n ...\n}\n" + severity: WARNING +- id: generic.nginx.security.request-host-used.request-host-used + languages: + - generic + message: "'$http_host' and '$host' variables may contain a malicious value from attacker controlled 'Host' request header. + Use an explicitly configured host value or a allow list for validation." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-290: Authentication Bypass by Spoofing' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md + - https://portswigger.net/web-security/host-header + semgrep.dev: + rule: + origin: community + r_id: 9044 + rule_id: qNUjGg + rv_id: 1262680 + url: https://semgrep.dev/playground/r/ExTExrN/generic.nginx.security.request-host-used.request-host-used + version_id: ExTExrN + shortlink: https://sg.run/4x3Z + source: https://semgrep.dev/r/generic.nginx.security.request-host-used.request-host-used + subcategory: + - audit + technology: + - nginx + vulnerability_class: + - Improper Authentication + paths: + include: + - '*conf*' + - '*nginx*' + - '*vhost*' + - '**/sites-available/*' + - '**/sites-enabled/*' + pattern-either: + - pattern: $http_host + - pattern: $host + severity: WARNING +- id: generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + languages: + - regex + message: Stripe Restricted API Key detected + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 9079 + rule_id: 5rUOWq + rv_id: 1262900 + url: + https://semgrep.dev/playground/r/K3TKkKj/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + version_id: K3TKkKj + shortlink: https://sg.run/ZvdL + source: + https://semgrep.dev/r/generic.secrets.security.detected-stripe-restricted-api-key.detected-stripe-restricted-api-key + source-rule-url: https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json + subcategory: + - audit + technology: + - secrets + - stripe + vulnerability_class: + - Hard-coded Secrets + pattern-regex: rk_live_[0-9a-zA-Z]{24} + severity: ERROR +- id: generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + languages: + - generic + message: Username and password in URI detected + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go + semgrep.dev: + rule: + origin: community + r_id: 9084 + rule_id: DbUple + rv_id: 1262903 + url: + https://semgrep.dev/playground/r/YDTZeZE/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + version_id: YDTZeZE + shortlink: https://sg.run/8yA4 + source: + https://semgrep.dev/r/generic.secrets.security.detected-username-and-password-in-uri.detected-username-and-password-in-uri + subcategory: + - vuln + technology: + - secrets + vulnerability_class: + - Hard-coded Secrets + patterns: + - pattern: $PROTOCOL://$...USERNAME:$...PASSWORD@$END + - metavariable-regex: + metavariable: $...USERNAME + regex: \A({?)([A-Za-z])([A-Za-z0-9_-]){5,31}(}?)\Z + - metavariable-regex: + metavariable: $...PASSWORD + regex: (?!.*[\s])(?=.*[0-9])(?=.*[a-z])(?=.*[A-Z])(?=.*[!"#$%&'()*+,-./:;<=>?@[\]^_`{|}~]){6,32} + - metavariable-regex: + metavariable: $PROTOCOL + regex: (.*http.*)|(.*sql.*)|(.*ftp.*)|(.*smtp.*) + severity: ERROR +- id: generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + languages: + - generic + message: Detects potential Google Maps API keys in code + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory' + description: Detects potential Google Maps API keys in code + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A3:2017 Sensitive Data Exposure + references: + - https://ozguralp.medium.com/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e + semgrep.dev: + rule: + origin: community + r_id: 52196 + rule_id: EwU3kN + rv_id: 945530 + url: + https://semgrep.dev/playground/r/NdTqkGz/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + version_id: NdTqkGz + severity: MEDIUM + shortlink: https://sg.run/DL5d + source: https://semgrep.dev/r/generic.secrets.security.google-maps-apikeyleak.google-maps-apikeyleak + subcategory: + - audit + technology: + - Google Maps + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-regex: ^(AIza[0-9A-Za-z_-]{35}(?!\S))$ + severity: WARNING +- id: generic.visualforce.security.ncino.html.usesriforcdns.use-SRI-for-CDNs + languages: + - generic + message: 'Consuming CDNs without including a SubResource Integrity (SRI) can expose your application and its users to compromised + code. SRIs allow you to consume specific versions of content where if even a single byte is compromised, the resource + will not be loaded. Add an integrity attribute to your + - pattern-not: + severity: ERROR +- id: generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + languages: + - generic + message: Visualforce Pages must have the cspHeader attribute set to true. This attribute is available in API version + 55 or higher. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://help.salesforce.com/s/articleView?id=sf.csp_trusted_sites.htm&type=5 + semgrep.dev: + rule: + origin: community + r_id: 72424 + rule_id: DbUj7d + rv_id: 1262907 + url: + https://semgrep.dev/playground/r/RGT0L0r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + version_id: RGT0L0r + shortlink: https://sg.run/yoj8 + source: https://semgrep.dev/r/generic.visualforce.security.ncino.xml.cspheaderattribute.csp-header-attribute + subcategory: + - vuln + technology: + - salesforce + - visualforce + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.page' + patterns: + - pattern: ... + - pattern-not: ... + - pattern-not: ...... + - pattern-not: ...... + severity: INFO +- id: generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + languages: + - generic + message: Visualforce Pages must use API version 55 or higher for required use of the cspHeader attribute set to true. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.salesforce.com/docs/atlas.en-us.api_meta.meta/api_meta/meta_pages.htm + semgrep.dev: + rule: + origin: community + r_id: 72425 + rule_id: WAUwJW + rv_id: 1262908 + url: + https://semgrep.dev/playground/r/A8Tgdgn/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + version_id: A8Tgdgn + shortlink: https://sg.run/rWr6 + source: + https://semgrep.dev/r/generic.visualforce.security.ncino.xml.visualforceapiversion.visualforce-page-api-version + subcategory: + - vuln + technology: + - salesforce + - visualforce + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.page-meta.xml' + patterns: + - pattern-inside: + - pattern-either: + - pattern-regex: '[>][0-9].[0-9][<]' + - pattern-regex: '[>][1-4][0-9].[0-9][<]' + - pattern-regex: '[>][5][0-4].[0-9][<]' + severity: WARNING +- id: go.aws-lambda.security.database-sqli.database-sqli + languages: + - go + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable + is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or + prepared statements instead. You can use prepared statements with the 'Prepare' and 'PrepareContext' calls. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pkg.go.dev/database/sql#DB.Query + semgrep.dev: + rule: + origin: community + r_id: 18232 + rule_id: WAUdJ7 + rv_id: 1262909 + url: https://semgrep.dev/playground/r/BjTkZkQ/go.aws-lambda.security.database-sqli.database-sqli + version_id: BjTkZkQ + shortlink: https://sg.run/e5e8 + source: https://semgrep.dev/r/go.aws-lambda.security.database-sqli.database-sqli + subcategory: + - vuln + technology: + - aws-lambda + - database + - sql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.Exec($QUERY,...) + - pattern: $DB.ExecContent($QUERY,...) + - pattern: $DB.Query($QUERY,...) + - pattern: $DB.QueryContext($QUERY,...) + - pattern: $DB.QueryRow($QUERY,...) + - pattern: $DB.QueryRowContext($QUERY,...) + - pattern-inside: "import \"database/sql\"\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - patterns: + - pattern-inside: "func $HANDLER($EVENT $TYPE) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - pattern-not-inside: "func $HANDLER($EVENT context.Context) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - focus-metavariable: $EVENT + severity: WARNING +- id: go.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - go + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18233 + rule_id: 0oUwqg + rv_id: 1262910 + url: https://semgrep.dev/playground/r/DkTRbRL/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: DkTRbRL + shortlink: https://sg.run/vX3Y + source: https://semgrep.dev/r/go.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - pattern: strconv.Atoi(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: "\"$SQLSTR\" + ...\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(\s*select|\s*delete|\s*insert|\s*create|\s*update|\s*alter|\s*drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + - pattern-not-inside: "log.$PRINT(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "func $HANDLER($CTX $CTXTYPE, $EVENT $TYPE, ...) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - patterns: + - pattern-inside: "func $HANDLER($EVENT $TYPE) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - pattern-not-inside: "func $HANDLER($EVENT context.Context) {...}\n...\nlambda.Start($HANDLER, ...)\n" + - focus-metavariable: $EVENT + severity: ERROR +- fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + id: go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + languages: + - go + message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs + the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' + flag by setting 'HttpOnly' to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + semgrep.dev: + rule: + origin: community + r_id: 9088 + rule_id: qNUj6g + rv_id: 1262911 + url: + https://semgrep.dev/playground/r/WrTqKqe/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + version_id: WrTqKqe + shortlink: https://sg.run/4xJZ + source: + https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-httponly.session-cookie-missing-httponly + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "&sessions.Options{\n ...,\n HttpOnly: true,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + id: go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + languages: + - go + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the + client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' + to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/user/session/session.go#L69 + semgrep.dev: + rule: + origin: community + r_id: 9089 + rule_id: lBU9kw + rv_id: 1262912 + url: + https://semgrep.dev/playground/r/0bTKzKk/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + version_id: 0bTKzKk + shortlink: https://sg.run/PJdE + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-missing-secure.session-cookie-missing-secure + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "&sessions.Options{\n ...,\n Secure: true,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (SameSite\s*:\s+)http.SameSiteNoneMode + replacement: \1http.SameSiteDefaultMode + id: go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + languages: + - go + message: Found SameSiteNoneMode setting in Gorilla session options. Consider setting SameSite to Lax, Strict or + Default for enhanced security. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://pkg.go.dev/github.com/gorilla/sessions#Options + semgrep.dev: + rule: + origin: community + r_id: 133074 + rule_id: YGUpGd4 + rv_id: 1262913 + url: + https://semgrep.dev/playground/r/K3TKkKB/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + version_id: K3TKkKB + shortlink: https://sg.run/x8Nwj + source: https://semgrep.dev/r/go.gorilla.security.audit.session-cookie-samesitenone.session-cookie-samesitenone + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cookie Security + patterns: + - pattern-inside: "&sessions.Options{\n ...,\n SameSite: http.SameSiteNoneMode,\n ...,\n}\n" + - pattern: "&sessions.Options{\n ...,\n}\n" + severity: WARNING +- id: go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + languages: + - go + message: 'The Origin header in the HTTP WebSocket handshake is used to guarantee that the connection accepted by the WebSocket + is from a trusted origin domain. Failure to enforce can lead to Cross Site Request Forgery (CSRF). As per "gorilla/websocket" + documentation: "A CheckOrigin function should carefully validate the request origin to prevent cross-site request forgery."' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/github.com/gorilla/websocket#Upgrader + semgrep.dev: + rule: + origin: community + r_id: 18430 + rule_id: ReUKdz + rv_id: 1262914 + url: + https://semgrep.dev/playground/r/qkTR7RP/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + version_id: qkTR7RP + shortlink: https://sg.run/xXpz + source: + https://semgrep.dev/r/go.gorilla.security.audit.websocket-missing-origin-check.websocket-missing-origin-check + subcategory: + - audit + technology: + - gorilla + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "import (\"github.com/gorilla/websocket\")\n...\n" + - patterns: + - pattern-not-inside: "$UPGRADER = websocket.Upgrader{..., CheckOrigin: $FN ,...}\n...\n" + - pattern-not-inside: "$UPGRADER.CheckOrigin = $FN2\n...\n" + - pattern: "$UPGRADER.Upgrade(...)\n" + severity: WARNING +- id: go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + languages: + - go + message: Detected usage of dangerous method $METHOD which does not escape inputs (see link in references). If the + argument is user-controlled, this can lead to SQL injection. When using $METHOD function, do not trust + user-submitted data and only allow approved list of input (possibly, use an allowlist approach). + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://gorm.io/docs/security.html#SQL-injection-Methods + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 24693 + rule_id: AbU5o3 + rv_id: 1262915 + url: + https://semgrep.dev/playground/r/l4TJRJK/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + version_id: l4TJRJK + shortlink: https://sg.run/R4qg + source: https://semgrep.dev/r/go.gorm.security.audit.gorm-dangerous-methods-usage.gorm-dangerous-method-usage + subcategory: + - vuln + technology: + - gorm + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: "($X: bool)\n" + pattern-sinks: + - patterns: + - pattern-inside: "import (\"gorm.io/gorm\")\n...\n" + - patterns: + - pattern-inside: "func $VAL(..., $GORM *gorm.DB,... ) {\n ...\n}\n" + - pattern-either: + - pattern: "$GORM. ... .$METHOD($VALUE)\n" + - pattern: "$DB := $GORM. ... .$ANYTHING(...)\n...\n$DB. ... .$METHOD($VALUE)\n" + - focus-metavariable: $VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(Order|Exec|Raw|Group|Having|Distinct|Select|Pluck)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: WARNING +- fix-regex: + regex: (.*)WithInsecure\(.*?\) + replacement: \1WithTransportCredentials(credentials.NewTLS()) + id: go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + languages: + - go + message: "Found an insecure gRPC connection using 'grpc.WithInsecure()'. This creates a connection without encryption to + a gRPC server. A malicious attacker could tamper with the gRPC message, which could compromise the machine. Instead, establish + a secure connection with an SSL certificate using the 'grpc.WithTransportCredentials()' function. You can create a create + credentials using a 'tls.Config{}' struct with 'credentials.NewTLS()'. The final fix looks like this: 'grpc.WithTransportCredentials(credentials.NewTLS())'." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + semgrep.dev: + rule: + origin: community + r_id: 9090 + rule_id: PeUZ4X + rv_id: 1262916 + url: + https://semgrep.dev/playground/r/YDTZeZB/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + version_id: YDTZeZB + shortlink: https://sg.run/J9yZ + source: https://semgrep.dev/r/go.grpc.security.grpc-client-insecure-connection.grpc-client-insecure-connection + subcategory: + - audit + technology: + - grpc + vulnerability_class: + - Other + pattern: $GRPC.Dial($ADDR, ..., $GRPC.WithInsecure(...), ...) + severity: ERROR +- id: go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + languages: + - go + message: Found an insecure gRPC server without 'grpc.Creds()' or options with credentials. This allows for a + connection without encryption to this server. A malicious attacker could tamper with the gRPC message, which could + compromise the machine. Include credentials derived from an SSL certificate in order to create a secure gRPC + connection. You can create credentials using 'credentials.NewServerTLSFromFile("cert.pem", "cert.key")'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-300: Channel Accessible by Non-Endpoint' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://blog.gopheracademy.com/advent-2019/go-grps-and-tls/#connection-without-encryption + semgrep.dev: + rule: + origin: community + r_id: 9091 + rule_id: JDUy0B + rv_id: 1262917 + url: + https://semgrep.dev/playground/r/6xT2923/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + version_id: 6xT2923 + shortlink: https://sg.run/5Q5l + source: https://semgrep.dev/r/go.grpc.security.grpc-server-insecure-connection.grpc-server-insecure-connection + subcategory: + - audit + technology: + - grpc + vulnerability_class: + - Other + mode: taint + pattern-sinks: + - pattern: grpc.NewServer($OPT, ...) + requires: OPTIONS and not CREDS + - pattern: grpc.NewServer() + requires: EMPTY_CONSTRUCTOR + pattern-sources: + - label: OPTIONS + pattern: grpc.ServerOption{ ... } + - label: CREDS + pattern: grpc.Creds(...) + - label: EMPTY_CONSTRUCTOR + pattern: grpc.NewServer() + severity: ERROR +- id: go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + languages: + - go + message: Detected the decoding of a JWT token without a verify step. Don't use `ParseUnverified` unless you know what + you're doing This method parses the token but doesn't validate the signature. It's only ever useful in cases where + you know the signature is valid (because it has been checked previously in the stack) and you want to extract values + from it. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + semgrep.dev: + rule: + origin: community + r_id: 9094 + rule_id: ReUgJJ + rv_id: 1262918 + url: + https://semgrep.dev/playground/r/o5TbDbq/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + version_id: o5TbDbq + shortlink: https://sg.run/Av66 + source: https://semgrep.dev/r/go.jwt-go.security.audit.jwt-parse-unverified.jwt-go-parse-unverified + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Improper Authentication + patterns: + - pattern-inside: "import \"github.com/dgrijalva/jwt-go\"\n...\n" + - pattern: "$JWT.ParseUnverified(...)\n" + severity: WARNING +- id: go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + languages: + - go + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9092 + rule_id: 5rUOWQ + rv_id: 1262919 + url: https://semgrep.dev/playground/r/zyTb2bz/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + version_id: zyTb2bz + shortlink: https://sg.run/Gej1 + source: https://semgrep.dev/r/go.jwt-go.security.jwt-none-alg.jwt-go-none-algorithm + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "import \"github.com/golang-jwt/jwt\"\n...\n" + - pattern-inside: "import \"github.com/dgrijalva/jwt-go\"\n...\n" + - pattern-either: + - pattern: "jwt.SigningMethodNone\n" + - pattern: jwt.UnsafeAllowNoneSignatureType + severity: ERROR +- id: go.jwt-go.security.jwt.hardcoded-jwt-key + languages: + - go + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9093 + rule_id: GdU7Ny + rv_id: 1262920 + url: https://semgrep.dev/playground/r/pZT0305/go.jwt-go.security.jwt.hardcoded-jwt-key + version_id: pZT0305 + shortlink: https://sg.run/Rod2 + source: https://semgrep.dev/r/go.jwt-go.security.jwt.hardcoded-jwt-key + subcategory: + - vuln + technology: + - jwt + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$TOKEN.SignedString($F)\n" + - focus-metavariable: $F + pattern-sources: + - patterns: + - pattern-inside: "[]byte(\"$F\")\n" + severity: WARNING +- id: go.lang.security.audit.crypto.bad_imports.insecure-module-used + languages: + - go + message: The package `net/http/cgi` is on the import blocklist. The package is vulnerable to httpoxy attacks + (CVE-2015-5386). It is recommended to use `net/http` or a web framework to build a web application instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://godoc.org/golang.org/x/crypto/sha3 + semgrep.dev: + rule: + origin: community + r_id: 9113 + rule_id: yyUnov + rv_id: 1262921 + url: https://semgrep.dev/playground/r/2KTv2vJ/go.lang.security.audit.crypto.bad_imports.insecure-module-used + version_id: 2KTv2vJ + shortlink: https://sg.run/l2gj + source: https://semgrep.dev/r/go.lang.security.audit.crypto.bad_imports.insecure-module-used + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import \"net/http/cgi\"\n...\n" + - pattern: "cgi.$FUNC(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + languages: + - go + message: Disabled host key verification detected. This allows man-in-the-middle attacks. Use the + 'golang.org/x/crypto/ssh/knownhosts' package to do host key verification. See + https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ to learn more about the problem and how to + fix it. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-322: Key Exchange without Entity Authentication' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://skarlso.github.io/2019/02/17/go-ssh-with-host-key-verification/ + - https://gist.github.com/Skarlso/34321a230cf0245018288686c9e70b2d + semgrep.dev: + rule: + origin: community + r_id: 9114 + rule_id: r6UrW9 + rv_id: 1262922 + url: + https://semgrep.dev/playground/r/X0TzyzN/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + version_id: X0TzyzN + shortlink: https://sg.run/Yv6X + source: https://semgrep.dev/r/go.lang.security.audit.crypto.insecure_ssh.avoid-ssh-insecure-ignore-host-key + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Improper Authentication + pattern: ssh.InsecureIgnoreHostKey() + severity: WARNING +- fix: "crypto/rand\n" + id: go.lang.security.audit.crypto.math_random.math-random-used + languages: + - go + message: Do not use `math/rand`. Use `crypto/rand` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#secure-random-number-generation + semgrep.dev: + rule: + origin: community + r_id: 9115 + rule_id: bwUwy8 + rv_id: 1262923 + url: https://semgrep.dev/playground/r/jQTn5nj/go.lang.security.audit.crypto.math_random.math-random-used + version_id: jQTn5nj + shortlink: https://sg.run/6nK6 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.math_random.math-random-used + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "import $RAND \"$MATH\"\n" + - pattern: "import \"$MATH\"\n" + - metavariable-regex: + metavariable: $MATH + regex: ^(math/rand(\/v[0-9]+)*)$ + - pattern-either: + - pattern-inside: "...\nrand.$FUNC(...)\n" + - pattern-inside: "...\n$RAND.$FUNC(...)\n" + - focus-metavariable: + - $MATH + severity: WARNING +- fix: "tls.Config{ $...CONF, MinVersion: tls.VersionTLS13 }\n" + id: go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + languages: + - go + message: "`MinVersion` is missing from this TLS configuration. By default, as of Go 1.22, TLS 1.2 is currently used as + the minimum. General purpose web applications should default to TLS 1.3 with all other protocols disabled. Only where + it is known that a web server must support legacy clients with unsupported an insecure browsers (such as Internet Explorer + 10), it may be necessary to enable TLS 1.0 to provide support. Add `MinVersion: tls.VersionTLS13' to the TLS configuration + to bump the minimum version to TLS 1.3." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://go.dev/doc/go1.22#minor_library_changes + - https://pkg.go.dev/crypto/tls#:~:text=MinVersion + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9116 + rule_id: NbUk4X + rv_id: 1262924 + url: + https://semgrep.dev/playground/r/1QTypyp/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + version_id: 1QTypyp + shortlink: https://sg.run/oxEN + source: https://semgrep.dev/r/go.lang.security.audit.crypto.missing-ssl-minversion.missing-ssl-minversion + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "tls.Config{ $...CONF }\n" + - pattern-not: "tls.Config{..., MinVersion: ..., ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.sha224-hash.sha224-hash + languages: + - go + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151749 + rule_id: GdUvElR + rv_id: 1262925 + url: https://semgrep.dev/playground/r/9lT4b4w/go.lang.security.audit.crypto.sha224-hash.sha224-hash + version_id: 9lT4b4w + shortlink: https://sg.run/ReJwY + source: https://semgrep.dev/r/go.lang.security.audit.crypto.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - patterns: + - pattern-inside: "import \"crypto/sha256\"\n...\n" + - pattern-either: + - pattern: "sha256.New224()\n" + - pattern: "sha256.Sum224(...)\n" + - patterns: + - pattern-inside: "import \"golang.org/x/crypto/sha3\"\n...\n" + - pattern-either: + - pattern: "sha3.New224()\n" + - pattern: "sha3.Sum224(...)\n" + severity: WARNING +- fix-regex: + regex: VersionSSL30 + replacement: VersionTLS13 + id: go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + languages: + - go + message: SSLv3 is insecure because it has known vulnerabilities. Starting with go1.14, SSLv3 will be removed. Instead, + use 'tls.VersionTLS13'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/doc/go1.14#crypto/tls + - https://www.us-cert.gov/ncas/alerts/TA14-290A + semgrep.dev: + rule: + origin: community + r_id: 9117 + rule_id: kxUkJ2 + rv_id: 1262926 + url: https://semgrep.dev/playground/r/yeTxpxj/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + version_id: yeTxpxj + shortlink: https://sg.run/zvE1 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.ssl.ssl-v3-is-insecure + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls_config.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern: 'tls.Config{..., MinVersion: $TLS.VersionSSL30, ...}' + severity: WARNING +- id: go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + languages: + - go + message: Detected an insecure CipherSuite via the 'tls' module. This suite is considered weak. Use the function + 'tls.CipherSuites()' to get a list of good cipher suites. See + https://golang.org/pkg/crypto/tls/#InsecureCipherSuites for why and what other cipher suites to use. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/crypto/tls/#InsecureCipherSuites + semgrep.dev: + rule: + origin: community + r_id: 9118 + rule_id: wdUJYk + rv_id: 1262927 + url: https://semgrep.dev/playground/r/rxTAKAZ/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + version_id: rxTAKAZ + shortlink: https://sg.run/px8N + source: https://semgrep.dev/r/go.lang.security.audit.crypto.tls.tls-with-insecure-cipher + source-rule-url: https://github.com/securego/gosec/blob/master/rules/tls.go + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.Config{..., CipherSuites: []$TYPE{..., tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_RC4_128_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, ...}\n" + - pattern: "tls.CipherSuite{..., TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, ...}\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + languages: + - go + message: Detected DES cipher algorithm which is insecure. The algorithm is considered weak and has been deprecated. + Use AES instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9121 + rule_id: eqU8B3 + rv_id: 1262930 + url: https://semgrep.dev/playground/r/kbTzGzA/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + version_id: kbTzGzA + shortlink: https://sg.run/jREA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-DES + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/des\"\n...\n" + - pattern-either: + - pattern: "des.NewTripleDESCipher(...)\n" + - pattern: "des.NewCipher(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + languages: + - go + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9119 + rule_id: x8Un6q + rv_id: 1262928 + url: https://semgrep.dev/playground/r/bZT535Y/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + version_id: bZT535Y + shortlink: https://sg.run/2xB5 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-md5 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/md5\"\n...\n" + - pattern-either: + - pattern: "md5.New()\n" + - pattern: "md5.Sum(...)\n" + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + languages: + - go + message: Detected RC4 cipher algorithm which is insecure. The algorithm has many known vulnerabilities. Use AES + instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9122 + rule_id: v8Unl0 + rv_id: 1262931 + url: https://semgrep.dev/playground/r/w8TRoRQ/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + version_id: w8TRoRQ + shortlink: https://sg.run/1ZAD + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-rc4 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import \"crypto/rc4\"\n...\n" + - pattern: rc4.NewCipher(...) + severity: WARNING +- id: go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + languages: + - go + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9120 + rule_id: OrU31O + rv_id: 1262929 + url: https://semgrep.dev/playground/r/NdTzyz1/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + version_id: NdTzyz1 + shortlink: https://sg.run/XBYA + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_crypto.use-of-sha1 + source-rule-url: https://github.com/securego/gosec#available-rules + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern-inside: "import \"crypto/sha1\"\n...\n" + - pattern-either: + - pattern: "sha1.New()\n" + - pattern: "sha1.Sum(...)\n" + severity: WARNING +- fix: "2048\n" + id: go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + languages: + - go + message: RSA keys should be at least 2048 bits + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 9123 + rule_id: d8UjY3 + rv_id: 1262932 + url: + https://semgrep.dev/playground/r/xyTjz8L/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + version_id: xyTjz8L + shortlink: https://sg.run/9oY4 + source: https://semgrep.dev/r/go.lang.security.audit.crypto.use_of_weak_rsa_key.use-of-weak-rsa-key + source-rule-url: https://github.com/securego/gosec/blob/master/rules/rsa.go + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "rsa.GenerateKey(..., $BITS)\n" + - pattern: "rsa.GenerateMultiPrimeKey(..., $BITS)\n" + - metavariable-comparison: + comparison: $BITS < 2048 + metavariable: $BITS + - focus-metavariable: + - $BITS + severity: WARNING +- id: go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + languages: + - go + message: Detected non-static command inside exec.Cmd. Audit the input to 'exec.Cmd'. If unverified user data can reach + this call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9108 + rule_id: 2ZUb8l + rv_id: 1262934 + url: https://semgrep.dev/playground/r/e1Tyjeg/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + version_id: e1Tyjeg + shortlink: https://sg.run/Dorj + source: https://semgrep.dev/r/go.lang.security.audit.dangerous-exec-cmd.dangerous-exec-cmd + subcategory: + - audit + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - patterns: + - pattern: "exec.Cmd {...,Path: $CMD,...}\n" + - pattern-not: "exec.Cmd {...,Path: \"...\",...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: $ARGS,...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{...},...}\n" + - pattern-not-inside: "$ARGS = []string{\"...\",...};\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n$ARGS = []string{$CMD,...};\n...\n" + - pattern-not-inside: "$CMD = exec.LookPath(\"...\");\n...\n$ARGS = []string{$CMD,...};\n...\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,...},...}\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",...},...}\n" + - pattern-not-inside: "$CMD,$ERR := exec.LookPath(\"...\");\n...\n" + - pattern-not-inside: "$CMD = \"...\";\n...\n" + - patterns: + - pattern-either: + - pattern: "exec.Cmd {...,Args: []string{\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\",\"-c\",$EXE,...},...}\n" + - patterns: + - pattern: "exec.Cmd {...,Args: []string{$CMD,\"-c\",$EXE,...},...}\n" + - pattern-inside: "$CMD,$ERR := exec.LookPath(\"=~/(sh|bash|ksh|csh|tcsh|zsh)/\");\n...\n" + - pattern-not: "exec.Cmd {...,Args: []string{\"...\",\"...\",\"...\",...},...}\n" + - pattern-not-inside: "$EXE = \"...\";\n...\n" + - pattern-inside: "import \"os/exec\"\n...\n" + severity: ERROR +- id: go.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - go + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can + use the `golang.org/x/crypto/bcrypt` package. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://pkg.go.dev/golang.org/x/crypto/bcrypt + semgrep.dev: + rule: + origin: community + r_id: 14688 + rule_id: 4bU1Wj + rv_id: 1262938 + url: https://semgrep.dev/playground/r/nWT2L9r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: nWT2L9r + shortlink: https://sg.run/4eOE + source: https://semgrep.dev/r/go.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5.New + - pattern: md5.Sum + severity: WARNING +- id: go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + languages: + - go + message: Detected a network listener listening on 0.0.0.0 or an empty string. This could unexpectedly expose the + server publicly as it binds to all available interfaces. Instead, specify another IP address that is not 0.0.0.0 nor + the empty string. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9125 + rule_id: nJUz3J + rv_id: 1262939 + url: https://semgrep.dev/playground/r/ExTExoK/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + version_id: ExTExoK + shortlink: https://sg.run/rdE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.bind_all.avoid-bind-to-all-interfaces + source-rule-url: https://github.com/securego/gosec + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: tls.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^0.0.0.0:.*$/", ...) + - pattern: tls.Listen($NETWORK, "=~/^:.*$/", ...) + - pattern: net.Listen($NETWORK, "=~/^:.*$/", ...) + severity: WARNING +- fix-regex: + regex: (HttpOnly\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + languages: + - go + message: A session cookie was detected without setting the 'HttpOnly' flag. The 'HttpOnly' flag for cookies instructs + the browser to forbid client-side scripts from reading the cookie which mitigates XSS attacks. Set the 'HttpOnly' + flag by setting 'HttpOnly' to 'true' in the Cookie. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9126 + rule_id: EwU2Z6 + rv_id: 1262940 + url: + https://semgrep.dev/playground/r/7ZTE3BW/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + version_id: 7ZTE3BW + shortlink: https://sg.run/b73e + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-httponly.cookie-missing-httponly + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n HttpOnly: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- fix-regex: + regex: (Secure\s*:\s+)false + replacement: \1true + id: go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + languages: + - go + message: A session cookie was detected without setting the 'Secure' flag. The 'secure' flag for cookies prevents the + client from transmitting the cookie over insecure channels such as HTTP. Set the 'Secure' flag by setting 'Secure' + to 'true' in the Options struct. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/0c34/govwa/blob/139693e56406b5684d2a6ae22c0af90717e149b8/util/cookie.go + - https://golang.org/src/net/http/cookie.go + semgrep.dev: + rule: + origin: community + r_id: 9127 + rule_id: 7KUQ8X + rv_id: 1262941 + url: + https://semgrep.dev/playground/r/LjTkgGE/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + version_id: LjTkgGE + shortlink: https://sg.run/N4G7 + source: https://semgrep.dev/r/go.lang.security.audit.net.cookie-missing-secure.cookie-missing-secure + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cookie Security + patterns: + - pattern-not-inside: "http.Cookie{\n ...,\n Secure: true,\n ...,\n}\n" + - pattern: "http.Cookie{\n ...,\n}\n" + severity: WARNING +- id: go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + languages: + - go + message: Detected a potentially dynamic ClientTrace. This occurred because semgrep could not find a static definition + for '$TRACE'. Dynamic ClientTraces are dangerous because they deserialize function code to run when certain Request + events occur, which could lead to code being run without your knowledge. Ensure that your ClientTrace is statically + defined. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/returntocorp/semgrep-rules/issues/518 + semgrep.dev: + rule: + origin: community + r_id: 9128 + rule_id: L1Uyjp + rv_id: 1262942 + url: + https://semgrep.dev/playground/r/8KT5rNv/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + version_id: 8KT5rNv + shortlink: https://sg.run/kXEK + source: https://semgrep.dev/r/go.lang.security.audit.net.dynamic-httptrace-clienttrace.dynamic-httptrace-clienttrace + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Code Injection + patterns: + - pattern-not-inside: "package $PACKAGE\n...\n&httptrace.ClientTrace { ... }\n...\n" + - pattern: httptrace.WithClientTrace($ANY, $TRACE) + severity: WARNING +- id: go.lang.security.audit.net.formatted-template-string.formatted-template-string + languages: + - go + message: Found a formatted template string passed to 'template.HTML()'. 'template.HTML()' does not escape contents. Be + absolutely sure there is no user-controlled data in this template. If user data can reach this template, you may + have a XSS vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/pkg/html/template/#HTML + semgrep.dev: + rule: + origin: community + r_id: 9129 + rule_id: 8GUjDW + rv_id: 1262943 + url: + https://semgrep.dev/playground/r/gETB7Pe/go.lang.security.audit.net.formatted-template-string.formatted-template-string + version_id: gETB7Pe + shortlink: https://sg.run/weE0 + source: https://semgrep.dev/r/go.lang.security.audit.net.formatted-template-string.formatted-template-string + subcategory: + - audit + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-not: template.HTML("..." + "...") + - pattern-either: + - pattern: template.HTML($T + $X, ...) + - pattern: template.HTML(fmt.$P("...", ...), ...) + - pattern: "$T = \"...\"\n...\n$T = $FXN(..., $T, ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T, $ERR = fmt.$P(\"...\", ...)\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = $X + $Y\n...\ntemplate.HTML($T, ...)\n" + - pattern: "$T = \"...\"\n...\n$OTHER, $ERR = fmt.$P(..., $T, ...)\n...\ntemplate.HTML($OTHER, ...)" + severity: WARNING +- id: go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + languages: + - go + message: "Detected usage of 'http.FileServer' as handler: this allows directory listing and an attacker could navigate through + directories looking for sensitive files. Be sure to disable directory listing or restrict access to specific directories/files." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-548: Exposure of Information Through Directory Listing' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/OWASP/Go-SCP + - https://cwe.mitre.org/data/definitions/548.html + semgrep.dev: + rule: + origin: community + r_id: 21300 + rule_id: 5rU9JO + rv_id: 1262944 + url: + https://semgrep.dev/playground/r/QkTGqX0/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + version_id: QkTGqX0 + shortlink: https://sg.run/4R8x + source: https://semgrep.dev/r/go.lang.security.audit.net.fs-directory-listing.fs-directory-listing + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern-inside: "$FS := http.FileServer(...)\n...\n" + - pattern-either: + - pattern: "http.ListenAndServe(..., $FS)\n" + - pattern: "http.ListenAndServeTLS(..., $FS)\n" + - pattern: "http.Handle(..., $FS)\n" + - pattern: "http.HandleFunc(..., $FS)\n" + - patterns: + - pattern: "http.$FN(..., http.FileServer(...))\n" + - metavariable-regex: + metavariable: $FN + regex: (ListenAndServe|ListenAndServeTLS|Handle|HandleFunc) + severity: WARNING +- fix: http.ListenAndServeTLS($ADDR, certFile, keyFile, $HANDLER) + id: go.lang.security.audit.net.use-tls.use-tls + languages: + - go + message: Found an HTTP server without TLS. Use 'http.ListenAndServeTLS' instead. See + https://golang.org/pkg/net/http/#ListenAndServeTLS for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://golang.org/pkg/net/http/#ListenAndServeTLS + semgrep.dev: + rule: + origin: community + r_id: 9134 + rule_id: PeUZ8X + rv_id: 1262948 + url: https://semgrep.dev/playground/r/JdTzxkn/go.lang.security.audit.net.use-tls.use-tls + version_id: JdTzxkn + shortlink: https://sg.run/dKbY + source: https://semgrep.dev/r/go.lang.security.audit.net.use-tls.use-tls + subcategory: + - audit + technology: + - go + vulnerability_class: + - Mishandled Sensitive Information + pattern: http.ListenAndServe($ADDR, $HANDLER) + severity: WARNING +- id: go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + languages: + - go + message: Found data going from url query parameters into formatted data written to ResponseWriter. This could be XSS + and should not be done. If you must do this, ensure your data is sanitized or escaped. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9135 + rule_id: JDUyXB + rv_id: 1262949 + url: + https://semgrep.dev/playground/r/5PTo1qr/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + version_id: 5PTo1qr + shortlink: https://sg.run/Zvon + source: + https://semgrep.dev/r/go.lang.security.audit.net.wip-xss-using-responsewriter-and-printf.wip-xss-using-responsewriter-and-printf + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "func $FUNC(..., $W http.ResponseWriter, ...) {\n ...\n var $TEMPLATE = \"...\"\n ...\n $W.Write([]byte(fmt.$PRINTF($TEMPLATE, + ...)), ...)\n ...\n}\n" + - pattern-either: + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n\ + $W.Write([]byte(fmt.$PRINTF(..., $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $DATA[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $INTERM, + ...)))\n" + - pattern: "$DATA, $ERR := r.URL.Query()[...]\n...\n$INTERM = $ANYTHING(..., $DATA, ...)\n...\n$W.Write([]byte(fmt.$PRINTF(..., + $INTERM, ...)))\n" + - pattern: "$PARAMS = r.URL.Query()\n...\n$DATA, $ERR := $PARAMS[...]\n...\n$W.Write([]byte(fmt.$PRINTF(..., $DATA, ...)))\n" + severity: WARNING +- id: go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + languages: + - go + message: Deserializing into `interface{}` allows arbitrary data structures and types, which can lead to security + vulnerabilities (CWE-502). Use a concrete struct type instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + references: + - https://cwe.mitre.org/data/definitions/502.html + semgrep.dev: + rule: + origin: community + r_id: 274359 + rule_id: 4bUAQDG + rv_id: 1409387 + url: + https://semgrep.dev/playground/r/ZRTDkjk/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + version_id: ZRTDkjk + shortlink: https://sg.run/6WbKL + source: + https://semgrep.dev/r/go.lang.security.deserialization.unsafe-deserialization-interface.go-unsafe-deserialization-interface + subcategory: + - vuln + technology: + - go + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-either: + - pattern: "var $VAR interface{}\n...\njson.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nyaml.Unmarshal($DATA, &$VAR)\n" + - pattern: "var $VAR interface{}\n...\nxml.Unmarshal($DATA, &$VAR)\n" + severity: WARNING +- fix: filepath.FromSlash(filepath.Clean("/"+strings.Trim($...INNER, "/"))) + id: go.lang.security.filepath-clean-misuse.filepath-clean-misuse + languages: + - go + message: '`Clean` is not intended to sanitize against path traversal attacks. This function is for finding the shortest + path name equivalent to the given input. Using `Clean` to sanitize file reads may expose this application to path traversal + attacks, where an attacker could access arbitrary files on the server. To fix this easily, write this: `filepath.FromSlash(path.Clean("/"+strings.Trim(req.URL.Path, + "/")))` However, a better solution is using the `SecureJoin` function in the package `filepath-securejoin`. See https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://pkg.go.dev/path#Clean + - http://technosophos.com/2016/03/31/go-quickly-cleaning-filepaths.html + - https://labs.detectify.com/2021/12/15/zero-day-path-traversal-grafana/ + - https://dzx.cz/2021/04/02/go_path_traversal/ + - https://pkg.go.dev/github.com/cyphar/filepath-securejoin#section-readme + semgrep.dev: + rule: + origin: community + r_id: 18235 + rule_id: qNUQJe + rv_id: 1262967 + url: https://semgrep.dev/playground/r/jQTn5Bj/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + version_id: jQTn5Bj + shortlink: https://sg.run/ZKzw + source: https://semgrep.dev/r/go.lang.security.filepath-clean-misuse.filepath-clean-misuse + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Path Traversal + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: "\"/\" + ...\n" + pattern-sinks: + - patterns: + - pattern-either: + - pattern: filepath.Clean($...INNER) + - pattern: path.Clean($...INNER) + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.raw-html-format.raw-html-format + languages: + - go + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. Use the `html/template` package which will safely render HTML + instead, or inspect that the HTML is rendered safely. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://blogtitle.github.io/robn-go-security-pearls-cross-site-scripting-xss/ + semgrep.dev: + rule: + origin: community + r_id: 14443 + rule_id: PeUonQ + rv_id: 1262968 + url: https://semgrep.dev/playground/r/1QTyp2p/go.lang.security.injection.raw-html-format.raw-html-format + version_id: 1QTyp2p + shortlink: https://sg.run/3r1G + source: https://semgrep.dev/r/go.lang.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: html.EscapeString(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: fmt.Printf("$HTMLSTR", ...) + - pattern: fmt.Sprintf("$HTMLSTR", ...) + - pattern: fmt.Fprintf($W, "$HTMLSTR", ...) + - pattern: '"$HTMLSTR" + ...' + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: WARNING +- id: go.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - go + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`db.Query("SELECT * FROM t WHERE id = ?", id)`) or a safe library. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://golang.org/doc/database/sql-injection + - https://www.stackhawk.com/blog/golang-sql-injection-guide-examples-and-prevention/ + semgrep.dev: + rule: + origin: community + r_id: 14689 + rule_id: PeUoqy + rv_id: 1409388 + url: https://semgrep.dev/playground/r/nWTQ5qD/go.lang.security.injection.tainted-sql-string.tainted-sql-string + version_id: nWTQ5qD + shortlink: https://sg.run/PbEq + source: https://semgrep.dev/r/go.lang.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - go + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: strconv.Atoi(...) + - pattern: "($X: bool)\n" + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\";\n...\n" + - pattern: $VAR += ... + - patterns: + - pattern-inside: "var $SB strings.Builder\n...\n" + - pattern-inside: "$SB.WriteString(\"$SQLSTR\")\n...\n$SB.String(...)\n" + - pattern: "$SB.WriteString(...)\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop).* + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$SQLSTR", ...) + - pattern: fmt.Sprintf("$SQLSTR", ...) + - pattern: fmt.Printf("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*%(v|s|q).* + pattern-sources: + - patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + severity: ERROR +- id: go.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - go + message: A request was found to be crafted from user-input `$REQUEST`. This can lead to Server-Side Request Forgery + (SSRF) vulnerabilities, potentially exposing sensitive data. It is recommend where possible to not allow user-input + to craft the base request, but to be treated as part of the path or query parameter. When user-input is necessary to + craft the request, it is recommended to follow OWASP best practices to prevent abuse, including using an allowlist. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://goteleport.com/blog/ssrf-attacks/ + semgrep.dev: + rule: + origin: community + r_id: 14391 + rule_id: AbUQLr + rv_id: 1262970 + url: https://semgrep.dev/playground/r/yeTxpOj/go.lang.security.injection.tainted-url-host.tainted-url-host + version_id: yeTxpOj + shortlink: https://sg.run/5DjW + source: https://semgrep.dev/r/go.lang.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - go + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$CLIENT := &http.Client{...}\n...\n" + - pattern: $CLIENT.$METHOD($URL, ...) + - pattern: http.$METHOD($URL, ...) + - metavariable-regex: + metavariable: $METHOD + regex: ^(Get|Head|Post|PostForm)$ + - patterns: + - pattern: "http.NewRequest(\"$METHOD\", $URL, ...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: ^(GET|HEAD|POST|POSTFORM)$ + - focus-metavariable: $URL + requires: INPUT and not CLEAN + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "($REQUEST : *http.Request).$ANYTHING\n" + - pattern: "($REQUEST : http.Request).$ANYTHING\n" + - metavariable-regex: + metavariable: $ANYTHING + regex: + ^(BasicAuth|Body|Cookie|Cookies|Form|FormValue|GetBody|Host|MultipartReader|ParseForm|ParseMultipartForm|PostForm|PostFormValue|Referer|RequestURI|Trailer|TransferEncoding|UserAgent|URL)$ + - label: CLEAN + patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + $INPUT\n" + - patterns: + - pattern-either: + - pattern: fmt.Fprintf($F, "$URLSTR", $INPUT, ...) + - pattern: fmt.Sprintf("$URLSTR", $INPUT, ...) + - pattern: fmt.Printf("$URLSTR", $INPUT, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: .*//[a-zA-Z0-10]+\..* + requires: INPUT + severity: WARNING +- id: html.security.plaintext-http-link.plaintext-http-link + languages: + - html + message: This link points to a plaintext HTTP URL. Prefer an encrypted HTTPS URL if possible. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/319.html + semgrep.dev: + rule: + origin: community + r_id: 39193 + rule_id: AbUnNo + rv_id: 1262976 + url: https://semgrep.dev/playground/r/xyTjzRL/html.security.plaintext-http-link.plaintext-http-link + version_id: xyTjzRL + shortlink: https://sg.run/RA5q + source: https://semgrep.dev/r/html.security.plaintext-http-link.plaintext-http-link + subcategory: + - vuln + technology: + - html + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: ... + - metavariable-regex: + metavariable: $URL + regex: ^(?i)http:// + severity: WARNING +- id: java.android.security.exported_activity.exported_activity + languages: + - generic + message: The application exports an activity. Any application on the device can launch the exported activity which may + compromise the integrity of your application or its data. Ensure that any exported activities do not have + privileged access to your application's control plane. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-926: Improper Export of Android Application Components' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A5:2021 Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/926.html + semgrep.dev: + rule: + origin: community + r_id: 60632 + rule_id: v8Ul0r + rv_id: 945629 + url: https://semgrep.dev/playground/r/rxT6rGR/java.android.security.exported_activity.exported_activity + version_id: rxT6rGR + shortlink: https://sg.run/eNGZ + source: https://semgrep.dev/r/java.android.security.exported_activity.exported_activity + subcategory: + - vuln + technology: + - Android + vulnerability_class: + - Other + paths: + exclude: + - sources/ + - classes3.dex + - '*.so' + include: + - '*AndroidManifest.xml' + patterns: + - pattern-not-inside: + - pattern-inside: " \n" + - pattern-either: + - pattern: "\n" + - pattern: " ... />\n" + severity: WARNING +- id: java.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - java + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18237 + rule_id: YGUl4z + rv_id: 1262977 + url: https://semgrep.dev/playground/r/O9TpxQN/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: O9TpxQN + shortlink: https://sg.run/EBYN + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\".concat(...)\n" + - patterns: + - pattern-inside: "StringBuilder $SB = new StringBuilder(\"$SQLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\";\n...\n" + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - pattern-not-inside: "System.out.$PRINTLN(...)\n" + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: "$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {\n ...\n}\n" + - pattern: "$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context + $CONTEXT) {\n ...\n}\n" + severity: ERROR +- id: java.aws-lambda.security.tainted-sqli.tainted-sqli + languages: + - java + message: Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if variables in + the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize user input instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18238 + rule_id: 6JUDWk + rv_id: 1262978 + url: https://semgrep.dev/playground/r/e1Tyj4g/java.aws-lambda.security.tainted-sqli.tainted-sqli + version_id: e1Tyj4g + shortlink: https://sg.run/7942 + source: https://semgrep.dev/r/java.aws-lambda.security.tainted-sqli.tainted-sqli + subcategory: + - vuln + technology: + - sql + - java + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: "(java.sql.Statement $STMT) = ...;\n" + - pattern: "(java.sql.PreparedStatement $STMT) = ...;\n" + - pattern: "$VAR = $CONN.prepareStatement(...)\n" + - pattern: "$PATH.queryForObject(...);\n" + - pattern: "(java.util.Map $STMT) = $PATH.queryForMap(...);\n" + - pattern: "(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;\n" + - patterns: + - pattern-inside: "(String $SQL) = \"$SQLSTR\" + ...;\n...\n" + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) + pattern-sources: + - patterns: + - focus-metavariable: $EVENT + - pattern-either: + - pattern: "$HANDLERTYPE $HANDLER($TYPE $EVENT, com.amazonaws.services.lambda.runtime.Context $CONTEXT) {\n ...\n}\n" + - pattern: "$HANDLERTYPE $HANDLER(InputStream $EVENT, OutputStream $OUT, com.amazonaws.services.lambda.runtime.Context + $CONTEXT) {\n ...\n}\n" + severity: WARNING +- id: java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + languages: + - java + message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise + the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Call + '.verify()' before using the token. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures + semgrep.dev: + rule: + origin: community + r_id: 9151 + rule_id: pKUOE9 + rv_id: 1262979 + url: + https://semgrep.dev/playground/r/vdT06Lp/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + version_id: vdT06Lp + shortlink: https://sg.run/Bk95 + source: https://semgrep.dev/r/java.java-jwt.security.audit.jwt-decode-without-verify.java-jwt-decode-without-verify + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Improper Authentication + patterns: + - pattern: "com.auth0.jwt.JWT.decode(...);\n" + - pattern-not-inside: "class $CLASS {\n ...\n $RETURNTYPE $FUNC (...) {\n ...\n $VERIFIER.verify(...);\n ...\n\ + \ }\n}" + severity: WARNING +- id: java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + languages: + - java + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9149 + rule_id: oqUeAn + rv_id: 1262980 + url: https://semgrep.dev/playground/r/d6Tyx8j/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + version_id: d6Tyx8j + shortlink: https://sg.run/RoDK + source: https://semgrep.dev/r/java.java-jwt.security.jwt-hardcode.java-jwt-hardcoded-secret + subcategory: + - vuln + technology: + - java + - secrets + - jwt + vulnerability_class: + - Hard-coded Secrets + patterns: + - pattern-either: + - pattern: "(Algorithm $ALG) = $ALGO.$HMAC(\"$Y\");\n" + - pattern: "$SECRET = \"$Y\";\n...\n(Algorithm $ALG) = $ALGO.$HMAC($SECRET);\n" + - pattern: "class $CLASS {\n ...\n $TYPE $SECRET = \"$Y\";\n ...\n $RETURNTYPE $FUNC (...) {\n ...\n (Algorithm + $ALG) = $ALGO.$HMAC($SECRET);\n ...\n }\n ...\n}\n" + - focus-metavariable: $Y + - metavariable-regex: + metavariable: $HMAC + regex: (HMAC384|HMAC256|HMAC512) + severity: WARNING +- id: java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + languages: + - java + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9150 + rule_id: zdUkzR + rv_id: 1262981 + url: https://semgrep.dev/playground/r/ZRTKADq/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + version_id: ZRTKADq + shortlink: https://sg.run/Av14 + source: https://semgrep.dev/r/java.java-jwt.security.jwt-none-alg.java-jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "$JWT.sign(com.auth0.jwt.algorithms.Algorithm.none());\n" + - pattern: "$NONE = com.auth0.jwt.algorithms.Algorithm.none();\n...\n$JWT.sign($NONE);\n" + - pattern: "class $CLASS {\n ...\n $TYPE $NONE = com.auth0.jwt.algorithms.Algorithm.none();\n ...\n $RETURNTYPE $FUNC + (...) {\n ...\n $JWT.sign($NONE);\n ...\n }\n ...\n}" + severity: ERROR +- id: java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + languages: + - java + message: Detected a potential path traversal. A malicious actor could control the location of this file, to include + going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths + are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.owasp.org/index.php/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9152 + rule_id: 2ZUb9l + rv_id: 1262984 + url: https://semgrep.dev/playground/r/7ZTE3KW/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + version_id: 7ZTE3KW + shortlink: https://sg.run/DoWj + source: https://semgrep.dev/r/java.jax-rs.security.jax-rs-path-traversal.jax-rs-path-traversal + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + subcategory: + - vuln + technology: + - jax-rs + vulnerability_class: + - Path Traversal + pattern-either: + - pattern: "$RETURNTYPE $FUNC (..., @PathParam(...) $TYPE $VAR, ...) {\n ...\n new File(..., $VAR, ...);\n ...\n}\n" + - pattern: "$RETURNTYPE $FUNC (..., @javax.ws.rs.PathParam(...) $TYPE $VAR, ...) {\n ...\n new File(..., $VAR, ...);\n\ + \ ...\n}" + severity: WARNING +- id: java.jboss.security.session_sqli.find-sql-string-concatenation + languages: + - java + message: In $METHOD, $X is used to construct a SQL query via string concatenation. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9153 + rule_id: X5U8rQ + rv_id: 1262986 + url: https://semgrep.dev/playground/r/8KT5r3v/java.jboss.security.session_sqli.find-sql-string-concatenation + version_id: 8KT5r3v + shortlink: https://sg.run/W8kA + source: https://semgrep.dev/r/java.jboss.security.session_sqli.find-sql-string-concatenation + subcategory: + - vuln + technology: + - jboss + vulnerability_class: + - SQL Injection + pattern-either: + - pattern: "$RETURN $METHOD(...,String $X,...){\n ...\n Session $SESSION = ...;\n ...\n String $QUERY = ... + $X + ...;\n\ + \ ...\n PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);\n ...\n ResultSet $RESULT = $PS.executeQuery();\n\ + \ ...\n}\n" + - pattern: "$RETURN $METHOD(...,String $X,...){\n ...\n String $QUERY = ... + $X + ...;\n ...\n Session $SESSION = ...;\n\ + \ ...\n PreparedStatement $PS = $SESSION.connection().prepareStatement($QUERY);\n ...\n ResultSet $RESULT = $PS.executeQuery();\n\ + \ ...\n}\n" + severity: ERROR +- id: java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + languages: + - java + message: Using less than 128 bits for Blowfish is considered insecure. Use 128 bits or more, or switch to use AES + instead. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9167 + rule_id: d8UjJ3 + rv_id: 1262989 + url: + https://semgrep.dev/playground/r/3ZT4X2r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + version_id: 3ZT4X2r + shortlink: https://sg.run/9o74 + source: https://semgrep.dev/r/java.lang.security.audit.blowfish-insufficient-key-size.blowfish-insufficient-key-size + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#BLOWFISH_KEY_SIZE + subcategory: + - audit + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$KEYGEN = KeyGenerator.getInstance(\"Blowfish\");\n...\n$KEYGEN.init($SIZE);\n" + - metavariable-comparison: + comparison: $SIZE < 128 + metavariable: $SIZE + severity: WARNING +- fix: "\"AES/GCM/NoPadding\"\n" + id: java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + languages: + - java + message: Using CBC with PKCS5Padding is susceptible to padding oracle attacks. A malicious actor could discern the + difference between plaintext with valid or invalid padding. Further, CBC mode does not include any integrity checks. + Use 'AES/GCM/NoPadding' instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://capec.mitre.org/data/definitions/463.html + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#cipher-modes + - https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY + semgrep.dev: + rule: + origin: community + r_id: 9168 + rule_id: ZqU5oD + rv_id: 1262990 + url: https://semgrep.dev/playground/r/44TEjbE/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + version_id: 44TEjbE + shortlink: https://sg.run/ydxr + source: https://semgrep.dev/r/java.lang.security.audit.cbc-padding-oracle.cbc-padding-oracle + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PADDING_ORACLE + subcategory: + - audit + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: Cipher.getInstance("=~/.*\/CBC\/PKCS5Padding/") + - pattern: "\"=~/.*\\/CBC\\/PKCS5Padding/\"\n" + severity: WARNING +- id: java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + languages: + - java + message: When data from an untrusted source is put into a logger and not neutralized correctly, an attacker could + forge log entries or include malicious content. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9173 + rule_id: 8GUjwW + rv_id: 1262995 + url: https://semgrep.dev/playground/r/RGT0LEr/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + version_id: RGT0LEr + shortlink: https://sg.run/wek0 + source: https://semgrep.dev/r/java.lang.security.audit.crlf-injection-logs.crlf-injection-logs + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#CRLF_INJECTION_LOGS + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Improper Validation + patterns: + - pattern-either: + - patterns: + - pattern-inside: "class $CLASS {\n ...\n Logger $LOG = ...;\n ...\n}\n" + - pattern-either: + - pattern-inside: "$X $METHOD(...,HttpServletRequest $REQ,...) {\n ...\n}\n" + - pattern-inside: "$X $METHOD(...,ServletRequest $REQ,...) {\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n HttpServletRequest $REQ = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n ServletRequest $REQ = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n Logger $LOG = ...;\n ...\n HttpServletRequest $REQ = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n Logger $LOG = ...;\n ...\n ServletRequest $REQ = ...;\n ...\n}\n" + - pattern-either: + - pattern: "String $VAL = $REQ.getParameter(...);\n...\n$LOG.$LEVEL(<... $VAL ...>);\n" + - pattern: "String $VAL = $REQ.getParameter(...);\n...\n$LOG.log($LEVEL,<... $VAL ...>);\n" + - pattern: "$LOG.$LEVEL(<... $REQ.getParameter(...) ...>);\n" + - pattern: "$LOG.log($LEVEL,<... $REQ.getParameter(...) ...>);\n" + severity: WARNING +- fix: "\"AES/GCM/NoPadding\"\n" + id: java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + languages: + - java + - kt + message: DES is considered deprecated. AES is the recommended cipher. Upgrade to use AES. See + https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard for more information. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.nist.gov/news-events/news/2005/06/nist-withdraws-outdated-data-encryption-standard + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 9191 + rule_id: PeUZNg + rv_id: 1262996 + url: + https://semgrep.dev/playground/r/A8TgdEn/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + version_id: A8TgdEn + shortlink: https://sg.run/5Q73 + source: https://semgrep.dev/r/java.lang.security.audit.crypto.des-is-deprecated.des-is-deprecated + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#DES_USAGE + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: $CIPHER.getInstance("=~/DES/.*/") + - pattern-inside: $CIPHER.getInstance("DES") + - pattern-either: + - pattern: "\"=~/DES/.*/\"\n" + - pattern: "\"DES\"\n" + severity: WARNING +- id: java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + languages: + - java + - kt + message: Triple DES (3DES or DESede) is considered deprecated. AES is the recommended cipher. Upgrade to use AES. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://csrc.nist.gov/News/2017/Update-to-Current-Use-and-Deprecation-of-TDEA + semgrep.dev: + rule: + origin: community + r_id: 9192 + rule_id: JDUy8J + rv_id: 1262997 + url: + https://semgrep.dev/playground/r/BjTkZyQ/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + version_id: BjTkZyQ + shortlink: https://sg.run/Geqn + source: https://semgrep.dev/r/java.lang.security.audit.crypto.desede-is-deprecated.desede-is-deprecated + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#TDES_USAGE + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "$CIPHER.getInstance(\"=~/DESede.*/\")\n" + - pattern: "$CRYPTO.KeyGenerator.getInstance(\"DES\")\n" + severity: WARNING +- id: java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + languages: + - java + message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows + an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See + https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::mode::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9193 + rule_id: 5rUOb6 + rv_id: 1262998 + url: https://semgrep.dev/playground/r/DkTRbwL/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + version_id: DkTRbwL + shortlink: https://sg.run/Ro9K + source: https://semgrep.dev/r/java.lang.security.audit.crypto.ecb-cipher.ecb-cipher + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "Cipher $VAR = $CIPHER.getInstance($MODE);\n" + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* + severity: WARNING +- id: java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + languages: + - java + message: 'GCM IV/nonce is reused: encryption can be totally useless' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-323: Reusing a Nonce, Key Pair in Encryption' + functional-categories: + - crypto::search::randomness::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 11908 + rule_id: GdUZZ3 + rv_id: 1263000 + url: https://semgrep.dev/playground/r/0bTKzGk/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + version_id: 0bTKzGk + shortlink: https://sg.run/Dww2 + source: https://semgrep.dev/r/java.lang.security.audit.crypto.gcm-nonce-reuse.gcm-nonce-reuse + source-rule-url: https://www.youtube.com/watch?v=r1awgAl90wM + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: new GCMParameterSpec(..., "...".getBytes(...), ...); + - pattern: byte[] $NONCE = "...".getBytes(...); ... new GCMParameterSpec(..., $NONCE, ...); + severity: ERROR +- id: java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + languages: + - java + message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use + a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9194 + rule_id: GdU7pw + rv_id: 1263001 + url: https://semgrep.dev/playground/r/K3TKkgB/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + version_id: K3TKkgB + shortlink: https://sg.run/AvA4 + source: https://semgrep.dev/r/java.lang.security.audit.crypto.no-null-cipher.no-null-cipher + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: new NullCipher(...); + - pattern: new javax.crypto.NullCipher(...); + severity: WARNING +- id: java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + languages: + - java + message: Initialization Vectors (IVs) for block ciphers should be randomly generated each time they are used. Using a + static IV means the same plaintext encrypts to the same ciphertext every time, weakening the strength of the + encryption. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/329.html + semgrep.dev: + rule: + origin: community + r_id: 9195 + rule_id: ReUgj1 + rv_id: 1263002 + url: + https://semgrep.dev/playground/r/qkTR7vP/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + version_id: qkTR7vP + shortlink: https://sg.run/BkB5 + source: + https://semgrep.dev/r/java.lang.security.audit.crypto.no-static-initialization-vector.no-static-initialization-vector + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#STATIC_IV + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "byte[] $IV = {\n ...\n};\n...\nnew IvParameterSpec($IV, ...);\n" + - pattern: "class $CLASS {\n byte[] $IV = {\n ...\n };\n ...\n $METHOD(...) {\n ...\n new + IvParameterSpec($IV, ...);\n ...\n }\n}\n" + severity: WARNING +- id: java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + languages: + - java + - kt + message: Using RSA without OAEP mode weakens the encryption. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::mode::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://rdist.root.org/2009/10/06/why-rsa-encryption-padding-is-critical/ + semgrep.dev: + rule: + origin: community + r_id: 9196 + rule_id: AbUzoj + rv_id: 1263003 + url: https://semgrep.dev/playground/r/l4TJRpK/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + version_id: l4TJRpK + shortlink: https://sg.run/DoOj + source: https://semgrep.dev/r/java.lang.security.audit.crypto.rsa-no-padding.rsa-no-padding + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_NO_PADDING + subcategory: + - vuln + technology: + - java + - kotlin + vulnerability_class: + - Cryptographic Issues + pattern: $CIPHER.getInstance("=~/RSA/[Nn][Oo][Nn][Ee]/NoPadding/") + severity: WARNING +- id: java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + languages: + - java + message: Detected use of a Java socket that is not encrypted. As a result, the traffic could be read by an attacker + intercepting the network traffic. Use an SSLSocket created by 'SSLSocketFactory' or 'SSLServerSocketFactory' + instead. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + functional-categories: + - net::search::crypto-config::java.net + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9197 + rule_id: BYUN3X + rv_id: 1263008 + url: + https://semgrep.dev/playground/r/RGT0LEj/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + version_id: RGT0LEj + shortlink: https://sg.run/W8zA + source: https://semgrep.dev/r/java.lang.security.audit.crypto.unencrypted-socket.unencrypted-socket + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNENCRYPTED_SOCKET + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: new ServerSocket(...) + - pattern: new Socket(...) + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + languages: + - java + message: "Use of AES with ECB mode detected. ECB doesn't provide message confidentiality and is not semantically secure + so should not be used. Instead, use a strong, secure cipher: Cipher.getInstance(\"AES/CBC/PKCS7PADDING\"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::mode::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + semgrep.dev: + rule: + origin: community + r_id: 48734 + rule_id: WAU2yA + rv_id: 1263009 + url: https://semgrep.dev/playground/r/A8TgdEo/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + version_id: A8TgdEo + shortlink: https://sg.run/dB2Y + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-aes-ecb.use-of-aes-ecb + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern: $CIPHER.getInstance("=~/AES/ECB.*/") + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + languages: + - java + message: 'Use of Blowfish was detected. Blowfish uses a 64-bit block size that makes it vulnerable to birthday attacks, + and is therefore considered non-compliant. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). + See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information.' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + semgrep.dev: + rule: + origin: community + r_id: 48735 + rule_id: 0oUR28 + rv_id: 1263010 + url: https://semgrep.dev/playground/r/BjTkZy0/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + version_id: BjTkZy0 + shortlink: https://sg.run/ZE4n + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-blowfish.use-of-blowfish + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern: $CIPHER.getInstance("Blowfish") + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + languages: + - java + message: "Use of AES with no settings detected. By default, java.crypto.Cipher uses ECB mode. ECB doesn't provide message + confidentiality and is not semantically secure so should not be used. Instead, use a strong, secure cipher: java.crypto.Cipher.getInstance(\"\ + AES/CBC/PKCS7PADDING\"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions for more information." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::mode::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + semgrep.dev: + rule: + origin: community + r_id: 48736 + rule_id: KxUB7Z + rv_id: 1263011 + url: + https://semgrep.dev/playground/r/DkTRbwy/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + version_id: DkTRbwy + shortlink: https://sg.run/nzKO + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-default-aes.use-of-default-aes + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "import javax;\n...\n" + - pattern-either: + - pattern: javax.crypto.Cipher.getInstance("AES") + - pattern: (javax.crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: "import javax.*;\n...\n" + - pattern-inside: "import javax.crypto;\n...\n" + - pattern-either: + - pattern: crypto.Cipher.getInstance("AES") + - pattern: (crypto.Cipher $CIPHER).getInstance("AES") + - patterns: + - pattern-either: + - pattern-inside: "import javax.crypto.*;\n...\n" + - pattern-inside: "import javax.crypto.Cipher;\n...\n" + - pattern-either: + - pattern: Cipher.getInstance("AES") + - pattern: (Cipher $CIPHER).getInstance("AES") + severity: WARNING +- fix: "getSha512Digest\n" + id: java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + languages: + - java + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use HMAC instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + functional-categories: + - crypto::search::hash-algorithm::org.apache.commons + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 39194 + rule_id: BYUGK0 + rv_id: 1263012 + url: + https://semgrep.dev/playground/r/WrTqK7K/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + version_id: WrTqK7K + shortlink: https://sg.run/AWL2 + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5-digest-utils.use-of-md5-digest-utils + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern: "$DU.$GET_ALGO().digest(...)\n" + - metavariable-pattern: + metavariable: $GET_ALGO + pattern: getMd5Digest + - metavariable-pattern: + metavariable: $DU + pattern: DigestUtils + - focus-metavariable: $GET_ALGO + severity: WARNING +- fix: "\"SHA-512\"\n" + id: java.lang.security.audit.crypto.use-of-md5.use-of-md5 + languages: + - java + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use HMAC instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + functional-categories: + - crypto::search::hash-algorithm::java.security + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17325 + rule_id: KxU5lW + rv_id: 1263013 + url: https://semgrep.dev/playground/r/0bTKzGX/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + version_id: 0bTKzGX + shortlink: https://sg.run/ryJn + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-md5.use-of-md5 + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Insecure Hashing Algorithm + patterns: + - pattern: "java.security.MessageDigest.getInstance($ALGO, ...);\n" + - metavariable-regex: + metavariable: $ALGO + regex: (?i)(.MD5.) + - focus-metavariable: $ALGO + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + languages: + - java + message: 'Use of RC2 was detected. RC2 is vulnerable to related-key attacks, and is therefore considered non-compliant. + Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + semgrep.dev: + rule: + origin: community + r_id: 48737 + rule_id: qNUzXG + rv_id: 1263014 + url: https://semgrep.dev/playground/r/K3TKkg0/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + version_id: K3TKkg0 + shortlink: https://sg.run/EEvA + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc2.use-of-rc2 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern: $CIPHER.getInstance("RC2") + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + languages: + - java + message: 'Use of RC4 was detected. RC4 is vulnerable to several attacks, including stream cipher attacks and bit flipping + attacks. Instead, use a strong, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + - https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html + semgrep.dev: + rule: + origin: community + r_id: 48738 + rule_id: lBUw8k + rv_id: 1263015 + url: https://semgrep.dev/playground/r/qkTR7vk/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + version_id: qkTR7vk + shortlink: https://sg.run/7OYR + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-rc4.use-of-rc4 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + pattern: $CIPHER.getInstance("RC4") + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + languages: + - java + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Instead, use PBKDF2 for password hashing or SHA256 or SHA512 for other + hash function applications. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17326 + rule_id: qNUWNn + rv_id: 1263016 + url: https://semgrep.dev/playground/r/l4TJRpL/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + version_id: l4TJRpL + shortlink: https://sg.run/bXNp + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha1.use-of-sha1 + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - patterns: + - pattern: "java.security.MessageDigest.getInstance(\"$ALGO\", ...);\n" + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: "$DU.getSha1Digest().digest(...)\n" + severity: WARNING +- id: java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + languages: + - java + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + functional-categories: + - crypto::search::hash-algorithm::javax.crypto + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151750 + rule_id: ReUDGEz + rv_id: 1263017 + url: https://semgrep.dev/playground/r/YDTZewo/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + version_id: YDTZewo + shortlink: https://sg.run/Ab2KQ + source: https://semgrep.dev/r/java.lang.security.audit.crypto.use-of-sha224.use-of-sha224 + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha3_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.getSha512_224Digest() + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha3_224Hex(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224(...) + - pattern: org.apache.commons.codec.digest.DigestUtils.sha512_224Hex(...) + - pattern: new + org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_224) + - pattern: new + org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA_512_224) + - pattern: new + org.apache.commons.codec.digest.DigestUtils(org.apache.commons.codec.digest.MessageDigestAlgorithms.SHA3_224) + - patterns: + - pattern: java.security.MessageDigest.getInstance("$ALGO", ...); + - metavariable-regex: + metavariable: $ALGO + regex: .*224 + severity: WARNING +- id: java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + languages: + - java + message: RSA keys should be at least 2048 bits based on NIST recommendation. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::java.security + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 9200 + rule_id: 0oU5P5 + rv_id: 1263019 + url: https://semgrep.dev/playground/r/o5TbDLY/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + version_id: o5TbDLY + shortlink: https://sg.run/4x6x + source: https://semgrep.dev/r/java.lang.security.audit.crypto.weak-rsa.use-of-weak-rsa-key + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "KeyPairGenerator $KEY = $G.getInstance(\"RSA\");\n...\n$KEY.initialize($BITS);\n" + - metavariable-comparison: + comparison: $BITS < 2048 + metavariable: $BITS + severity: WARNING +- id: java.lang.security.audit.formatted-sql-string.formatted-sql-string + languages: + - java + message: Detected a formatted string in a SQL statement. This could lead to SQL injection if variables in the SQL + statement are not properly sanitized. Use a prepared statements (java.sql.PreparedStatement) instead. You can obtain + a PreparedStatement using 'connection.prepareStatement'. + metadata: + asvs: + control_id: 5.3.5 Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://docs.oracle.com/javase/tutorial/jdbc/basics/prepared.html#create_ps + - https://software-security.sans.org/developer-how-to/fix-sql-injection-in-java-using-prepared-callable-statement + semgrep.dev: + rule: + origin: community + r_id: 9175 + rule_id: QrUzxR + rv_id: 1409389 + url: https://semgrep.dev/playground/r/ExTeyBP/java.lang.security.audit.formatted-sql-string.formatted-sql-string + version_id: ExTeyBP + shortlink: https://sg.run/OPXp + source: https://semgrep.dev/r/java.lang.security.audit.formatted-sql-string.formatted-sql-string + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SQL_INJECTION + subcategory: + - vuln + technology: + - java + vulnerability_class: + - SQL Injection + mode: taint + options: + taint_assume_safe_booleans: true + taint_assume_safe_numbers: true + pattern-propagators: + - from: $X + pattern: (StringBuffer $S).append($X) + to: $S + - from: $X + pattern: (StringBuilder $S).append($X) + to: $S + pattern-sanitizers: + - patterns: + - pattern: (CriteriaBuilder $CB).$ANY(...) + pattern-sinks: + - patterns: + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE *$/" ...>) + - pattern-not: $S.$SQLFUNC(<... "=~/.*TABLE %s$/" ...>) + - pattern-either: + - pattern: (Statement $S).$SQLFUNC(...) + - pattern: (PreparedStatement $P).$SQLFUNC(...) + - pattern: (Connection $C).createStatement(...).$SQLFUNC(...) + - pattern: (Connection $C).prepareStatement(...).$SQLFUNC(...) + - pattern: (EntityManager $EM).$SQLFUNC(...) + - metavariable-regex: + metavariable: $SQLFUNC + regex: execute|executeQuery|createQuery|query|addBatch|nativeSQL|create|prepare + requires: CONCAT + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ)\n" + - patterns: + - pattern-inside: "$ANNOT $FUNC (..., $INPUT, ...) {\n ...\n}\n" + - pattern: (String $INPUT) + - focus-metavariable: $INPUT + - label: CONCAT + patterns: + - pattern-either: + - pattern: $X + $INPUT + - pattern: $X += $INPUT + - pattern: String.format(..., $INPUT, ...) + - pattern: String.join(..., $INPUT, ...) + - pattern: (String $STR).concat($INPUT) + - pattern: $INPUT.concat(...) + - patterns: + - pattern-either: + - pattern: $STRB.append($INPUT) + - pattern: new $STRB(..., $INPUT, ...) + - metavariable-type: + metavariable: $STRB + type: StringBuilder + requires: INPUT + severity: ERROR +- id: java.lang.security.audit.http-response-splitting.http-response-splitting + languages: + - java + message: Older Java application servers are vulnerable to HTTP response splitting, which may occur if an HTTP request + can be injected with CRLF characters. This finding is reported for completeness; it is recommended to ensure your + environment is not affected by testing this yourself. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.owasp.org/index.php/HTTP_Response_Splitting + semgrep.dev: + rule: + origin: community + r_id: 9176 + rule_id: 3qUPyK + rv_id: 1263023 + url: + https://semgrep.dev/playground/r/X0Tzykw/java.lang.security.audit.http-response-splitting.http-response-splitting + version_id: X0Tzykw + shortlink: https://sg.run/eL0l + source: https://semgrep.dev/r/java.lang.security.audit.http-response-splitting.http-response-splitting + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#HTTP_RESPONSE_SPLITTING + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Improper Validation + pattern-either: + - pattern: "$VAR = $REQ.getParameter(...);\n...\n$COOKIE = new Cookie(..., $VAR, ...);\n...\n$RESP.addCookie($COOKIE, ...);\n" + - patterns: + - pattern-inside: "$RETTYPE $FUNC(...,@PathVariable $TYPE $VAR, ...) {\n ...\n}\n" + - pattern: "$COOKIE = new Cookie(..., $VAR, ...);\n...\n$RESP.addCookie($COOKIE, ...);\n" + severity: INFO +- id: java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + languages: + - java + message: Insecure SMTP connection detected. This connection will trust any SSL certificate. Enable certificate + verification by setting 'email.setSSLCheckServerIdentity(true)'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-297: Improper Validation of Certificate with Host Mismatch' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 9177 + rule_id: 4bUkrW + rv_id: 1263024 + url: + https://semgrep.dev/playground/r/jQTn5Dv/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + version_id: jQTn5Dv + shortlink: https://sg.run/vzN4 + source: https://semgrep.dev/r/java.lang.security.audit.insecure-smtp-connection.insecure-smtp-connection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#INSECURE_SMTP_SSL + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Improper Authentication + patterns: + - pattern-not-inside: "$EMAIL.setSSLCheckServerIdentity(true);\n...\n" + - pattern-inside: "$EMAIL = new SimpleEmail(...);\n...\n" + - pattern: $EMAIL.send(...); + severity: WARNING +- id: java.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - java + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as PBKDF2 or bcrypt. + You can use `javax.crypto.SecretKeyFactory` with `SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1")` or, if using + Spring, `org.springframework.security.crypto.bcrypt`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#SecretKeyFactory + - https://docs.spring.io/spring-security/site/docs/current/api/org/springframework/security/crypto/bcrypt/BCryptPasswordEncoder.html + semgrep.dev: + rule: + origin: community + r_id: 14690 + rule_id: JDULAW + rv_id: 1263029 + url: https://semgrep.dev/playground/r/bZT53QB/java.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: bZT53QB + shortlink: https://sg.run/JxEQ + source: https://semgrep.dev/r/java.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - java + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - patterns: + - pattern: $MODEL.$METHOD(...); + - metavariable-regex: + metavariable: $METHOD + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-inside: "$TYPE $MD = MessageDigest.getInstance(\"MD5\");\n...\n" + - pattern: $MD.digest(...); + severity: WARNING +- id: java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into a SQL sink or statement. This could lead to SQL injection + if variables in the SQL statement are not properly sanitized. Use parameterized SQL queries or properly sanitize + user input instead. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18239 + rule_id: oqUBJG + rv_id: 1409390 + url: + https://semgrep.dev/playground/r/7ZTKJNj/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + version_id: 7ZTKJNj + shortlink: https://sg.run/Lg56 + source: + https://semgrep.dev/r/java.lang.security.audit.sqli.tainted-sql-from-http-request.tainted-sql-from-http-request + subcategory: + - vuln + technology: + - sql + - java + - servlets + - spring + vulnerability_class: + - SQL Injection + mode: taint + options: + taint_assume_safe_booleans: true + taint_assume_safe_numbers: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.sql.CallableStatement $STMT) = ...; \n" + - pattern: "(java.sql.Statement $STMT) = ...;\n...\n$OUTPUT = $STMT.$FUNC(...);\n" + - pattern: "(java.sql.PreparedStatement $STMT) = ...;\n" + - pattern: "$VAR = $CONN.prepareStatement(...)\n" + - pattern: "$PATH.queryForObject(...);\n" + - pattern: "(java.util.Map $STMT) = $PATH.queryForMap(...);\n" + - pattern: "(org.springframework.jdbc.support.rowset.SqlRowSet $STMT) = ...;\n" + - pattern: "(org.springframework.jdbc.core.JdbcTemplate $TEMPL).batchUpdate(...)\n" + - patterns: + - pattern-inside: "(String $SQL) = \"$SQLSTR\" + ...;\n...\n" + - pattern: $PATH.$SQLCMD(..., $SQL, ...); + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(^SELECT.* | ^INSERT.* | ^UPDATE.*) + - metavariable-regex: + metavariable: $SQLCMD + regex: (execute|query|executeUpdate|batchUpdate) + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ).$REQFUNC(...)\n" + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: + (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + severity: WARNING +- id: java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into a 'ProcessBuilder' or 'exec' command. This could lead to + command injection if variables passed into the exec commands are not properly sanitized. Instead, avoid using these + OS commands with user-supplied input, or, if you must use these commands, use a whitelist of specific values. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18240 + rule_id: zdUWrg + rv_id: 1263042 + url: + https://semgrep.dev/playground/r/LjTkg9J/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + version_id: LjTkg9J + shortlink: https://sg.run/8zPN + source: https://semgrep.dev/r/java.lang.security.audit.tainted-cmd-from-http-request.tainted-cmd-from-http-request + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(ProcessBuilder $PB) = ...;\n" + - patterns: + - pattern: "(Process $P) = ...;\n" + - pattern-not: "(Process $P) = (java.lang.Runtime $R).exec(...);\n" + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, ...); + - focus-metavariable: $CMD + - patterns: + - pattern-either: + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n...\n$PB.command($ARGLIST);\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(ProcessBuilder $PB) = ...;\n" + - pattern-inside: "(java.util.List<$TYPE> $ARGLIST) = ...; \n...\n(Process $P) = ...;\n" + - pattern: "$ARGLIST.add(...);\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ)\n" + - patterns: + - pattern-inside: "(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);\n...\nfor (javax.servlet.http.Cookie + $COOKIE: $COOKIES) {\n ...\n}\n" + - pattern: "$COOKIE.getValue(...)\n" + severity: ERROR +- id: java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into the environment variables of an 'exec' command. Instead, + call the command with user-supplied arguments by using the overloaded method with one String array as the argument. + `exec({"command", "arg1", "arg2"})`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-454: External Initialization of Trusted Variables or Data Stores' + cwe2021-top25: false + cwe2022-top25: false + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 70981 + rule_id: nJULjy + rv_id: 1409391 + url: + https://semgrep.dev/playground/r/LjTRL6W/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + version_id: LjTRL6W + shortlink: https://sg.run/EJAB + source: https://semgrep.dev/r/java.lang.security.audit.tainted-env-from-http-request.tainted-env-from-http-request + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Other + mode: taint + pattern-sinks: + - patterns: + - pattern: (java.lang.Runtime $R).exec($CMD, $ENV_ARGS, ...); + - focus-metavariable: $ENV_ARGS + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ)\n" + - patterns: + - pattern-inside: "(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);\n...\nfor (javax.servlet.http.Cookie + $COOKIE: $COOKIES) {\n ...\n}\n" + - pattern: "$COOKIE.getValue(...)\n" + severity: ERROR +- id: java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into an LDAP query. This could lead to LDAP injection if the + input is not properly sanitized, which could result in attackers modifying objects in the LDAP tree structure. + Ensure data passed to an LDAP query is not controllable or properly sanitize the data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sensei.securecodewarrior.com/recipes/scw%3Ajava%3ALDAP-injection + semgrep.dev: + rule: + origin: community + r_id: 18241 + rule_id: pKUXAv + rv_id: 1409392 + url: + https://semgrep.dev/playground/r/8KT3Pe6/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + version_id: 8KT3Pe6 + shortlink: https://sg.run/gRg0 + source: + https://semgrep.dev/r/java.lang.security.audit.tainted-ldapi-from-http-request.tainted-ldapi-from-http-request + subcategory: + - vuln + technology: + - java + vulnerability_class: + - LDAP Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(javax.naming.directory.InitialDirContext $IDC).search(...)\n" + - pattern: "(javax.naming.directory.DirContext $CTX).search(...)\n" + - pattern-not: "(javax.naming.directory.InitialDirContext $IDC).search($Y, \"...\", ...)\n" + - pattern-not: "(javax.naming.directory.DirContext $CTX).search($Y, \"...\", ...)\n" + pattern-sources: + - patterns: + - pattern: (HttpServletRequest $REQ) + severity: WARNING +- id: java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into a session command, like `setAttribute`. User input into + such a command could lead to an attacker inputting malicious code into your session parameters, blurring the line + between what's trusted and untrusted, and therefore leading to a trust boundary violation. This could lead to + programmers trusting unvalidated data. Instead, thoroughly sanitize user input before passing it into such function + calls. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-501: Trust Boundary Violation' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 18242 + rule_id: 2ZU7Eo + rv_id: 1409393 + url: + https://semgrep.dev/playground/r/gETrv9j/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + version_id: gETrv9j + shortlink: https://sg.run/QbDZ + source: + https://semgrep.dev/r/java.lang.security.audit.tainted-session-from-http-request.tainted-session-from-http-request + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Other + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: (HttpServletRequest $REQ).getSession().$FUNC($NAME, $VALUE); + - metavariable-regex: + metavariable: $FUNC + regex: ^(putValue|setAttribute)$ + - focus-metavariable: $VALUE + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: "(HttpServletRequest $REQ).$FUNC(...)\n" + - pattern-not: "(HttpServletRequest $REQ).getSession()\n" + - patterns: + - pattern-inside: "(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);\n...\nfor (javax.servlet.http.Cookie + $COOKIE: $COOKIES) {\n ...\n}\n" + - pattern: "$COOKIE.getValue(...)\n" + - patterns: + - pattern-inside: "$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(... );\n...\n" + - pattern: "$PARAM = $VALS[$INDEX];\n" + - patterns: + - pattern-inside: "$HEADERS = (HttpServletRequest $REQ).getHeaders(...);\n...\n$PARAM = $HEADERS.$FUNC(...);\n...\n" + - pattern: "java.net.URLDecoder.decode($PARAM, ...)\n" + severity: WARNING +- id: java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + languages: + - java + message: Detected input from a HTTPServletRequest going into a XPath evaluate or compile command. This could lead to + xpath injection if variables passed into the evaluate or compile commands are not properly sanitized. Xpath + injection could lead to unauthorized access to sensitive information in XML documents. Instead, thoroughly sanitize + user input or use parameterized xpath queries if you can. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18243 + rule_id: X5U5nj + rv_id: 1409394 + url: + https://semgrep.dev/playground/r/QkTERKP/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + version_id: QkTERKP + shortlink: https://sg.run/3BvK + source: + https://semgrep.dev/r/java.lang.security.audit.tainted-xpath-from-http-request.tainted-xpath-from-http-request + subcategory: + - vuln + technology: + - java + vulnerability_class: + - XPath Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(javax.xml.xpath.XPath $XP).evaluate(...)\n" + - pattern: "(javax.xml.xpath.XPath $XP).compile(...).evaluate(...)\n" + pattern-sources: + - patterns: + - pattern: "(HttpServletRequest $REQ).$FUNC(...)\n" + severity: WARNING +- id: java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + languages: + - java + message: Application redirects to a destination URL specified by a user-supplied parameter that is not validated. This + could direct users to malicious locations. Consider using an allowlist to validate URLs. + metadata: + asvs: + control_id: 5.1.5 Open Redirect + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9186 + rule_id: WAUo0p + rv_id: 1263048 + url: https://semgrep.dev/playground/r/PkTR329/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + version_id: PkTR329 + shortlink: https://sg.run/Q51P + source: https://semgrep.dev/r/java.lang.security.audit.unvalidated-redirect.unvalidated-redirect + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Open Redirect + pattern-either: + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {\n ...\n $RES.sendRedirect($URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {\n ...\n $RES.sendRedirect($URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {\n ...\n String $URL = $REQ.getParameter(...);\n\ + \ ...\n $RES.sendRedirect($URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {\n ...\n String $URL = $REQ.getParameter(...);\n\ + \ ...\n $RES.sendRedirect($URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n HttpServletResponse $RES = ...;\n ...\n $RES.sendRedirect($URL);\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {\n ...\n $RES.sendRedirect($REQ.getParameter(...));\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {\n ...\n $RES.sendRedirect($REQ.getParameter(...));\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,String $URL,...) {\n ...\n $RES.addHeader(\"Location\",$URL);\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...,HttpServletResponse $RES,...) {\n ...\n $RES.addHeader(\"Location\",$URL);\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {\n ...\n String $URL = $REQ.getParameter(...);\n\ + \ ...\n $RES.addHeader(\"Location\",$URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {\n ...\n String $URL = $REQ.getParameter(...);\n\ + \ ...\n $RES.addHeader(\"Location\",$URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n HttpServletResponse $RES = ...;\n ...\n $RES.addHeader(\"Location\"\ + ,$URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletRequest $REQ,...,HttpServletResponse $RES,...) {\n ...\n $RES.addHeader(\"Location\"\ + ,$REQ.getParameter(...));\n ...\n}\n" + - pattern: "$X $METHOD(...,HttpServletResponse $RES,...,HttpServletRequest $REQ,...) {\n ...\n $RES.addHeader(\"Location\"\ + ,$REQ.getParameter(...));\n ...\n}" + severity: WARNING +- fix-regex: + regex: (.*?)\.getInstance\(.*?\) + replacement: \1.getInstance("TLSv1.2") + id: java.lang.security.audit.weak-ssl-context.weak-ssl-context + languages: + - java + message: An insecure SSL context was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak + encryption and are deprecated. Use SSLContext.getInstance("TLSv1.2") for the best security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + semgrep.dev: + rule: + origin: community + r_id: 9188 + rule_id: KxUb1k + rv_id: 1263050 + url: https://semgrep.dev/playground/r/5PTo1rW/java.lang.security.audit.weak-ssl-context.weak-ssl-context + version_id: 5PTo1rW + shortlink: https://sg.run/4x7E + source: https://semgrep.dev/r/java.lang.security.audit.weak-ssl-context.weak-ssl-context + source_rule_url: https://find-sec-bugs.github.io/bugs.htm#SSL_CONTEXT + subcategory: + - audit + technology: + - java + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-not: SSLContext.getInstance("TLSv1.3") + - pattern-not: SSLContext.getInstance("TLSv1.2") + - pattern: SSLContext.getInstance("...") + severity: WARNING +- id: java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + languages: + - java + message: Detected a request with potential user-input going into a OutputStream or Writer object. This bypasses any + view or template environments, including HTML escaping, which may expose this application to cross-site scripting + (XSS) vulnerabilities. Consider using a view technology such as JavaServer Faces (JSFs) which automatically escapes + HTML views. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www3.ntu.edu.sg/home/ehchua/programming/java/JavaServerFaces.html + semgrep.dev: + rule: + origin: community + r_id: 9211 + rule_id: j2Uv7B + rv_id: 1263055 + url: + https://semgrep.dev/playground/r/DkTRbXy/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + version_id: DkTRbXy + shortlink: https://sg.run/KlRL + source: https://semgrep.dev/r/java.lang.security.audit.xss.no-direct-response-writer.no-direct-response-writer + subcategory: + - vuln + technology: + - java + - servlets + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) + - pattern: org.apache.commons.lang.StringEscapeUtils.escapeHtml(...) + - pattern: org.springframework.web.util.HtmlUtils.htmlEscape(...) + - pattern: org.owasp.esapi.ESAPI.encoder().encodeForHTML(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(HttpServletResponse $RESPONSE).getWriter(...).$WRITE(...)\n" + - pattern: "(HttpServletResponse $RESPONSE).getOutputStream(...).$WRITE(...)\n" + - pattern: "(java.io.PrintWriter $WRITER).$WRITE(...)\n" + - pattern: "(PrintWriter $WRITER).$WRITE(...)\n" + - pattern: "(javax.servlet.ServletOutputStream $WRITER).$WRITE(...)\n" + - pattern: "(ServletOutputStream $WRITER).$WRITE(...)\n" + - pattern: "(java.io.OutputStream $WRITER).$WRITE(...)\n" + - pattern: "(OutputStream $WRITER).$WRITE(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ).$REQFUNC(...)\n" + - pattern: "(ServletRequest $REQ).$REQFUNC(...) \n" + - metavariable-regex: + metavariable: $REQFUNC + regex: + (getInputStream|getParameter|getParameterMap|getParameterValues|getReader|getCookies|getHeader|getHeaderNames|getHeaders|getPart|getParts|getQueryString) + severity: WARNING +- id: + java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + languages: + - java + message: DOCTYPE declarations are enabled for $DBFACTORY. Without prohibiting external entity declarations, this is + vulnerable to XML external entity attacks. Disable this by setting the feature + "http://apache.org/xml/features/disallow-doctype-decl" to true. Alternatively, allow DOCTYPE declarations and only + prohibit external entities declarations. This can be done by setting the features + "http://xml.org/sax/features/external-general-entities" and + "http://xml.org/sax/features/external-parameter-entities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + semgrep.dev: + rule: + origin: community + r_id: 18244 + rule_id: j2UrJ8 + rv_id: 1263057 + url: + https://semgrep.dev/playground/r/0bTKzgX/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + version_id: 0bTKzgX + shortlink: https://sg.run/4Dv5 + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-false.documentbuilderfactory-disallow-doctype-decl-false + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + patterns: + - pattern: $DBFACTORY.setFeature("http://apache.org/xml/features/disallow-doctype-decl", false); + - pattern-not-inside: "$RETURNTYPE $METHOD(...){\n ...\n $DBF.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false);\n ...\n $DBF.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n ...\n}\n" + - pattern-not-inside: "$RETURNTYPE $METHOD(...){\n ...\n $DBF.setFeature(\"http://xml.org/sax/features/external-parameter-entities\"\ + , false);\n ...\n $DBF.setFeature(\"http://xml.org/sax/features/external-general-entities\", false);\n ...\n}\n" + - pattern-not-inside: "$RETURNTYPE $METHOD(...){\n ...\n $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\");\n\ + \ ...\n $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, \"\");\n ...\n}\n" + - pattern-not-inside: "$RETURNTYPE $METHOD(...){\n ...\n $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_SCHEMA, \"\");\n\ + \ ...\n $DBF.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\");\n ...\n}\n" + severity: ERROR +- fix: "$FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n$FACTORY.newDocumentBuilder();\n" + id: + java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + languages: + - java + message: DOCTYPE declarations are enabled for this DocumentBuilderFactory. This is vulnerable to XML external entity + attacks. Disable this by setting the feature "http://apache.org/xml/features/disallow-doctype-decl" to true. + Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by + setting the features "http://xml.org/sax/features/external-general-entities" and + "http://xml.org/sax/features/external-parameter-entities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + semgrep.dev: + rule: + origin: community + r_id: 18245 + rule_id: 10UPQB + rv_id: 1263058 + url: + https://semgrep.dev/playground/r/K3TKk80/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + version_id: K3TKk80 + shortlink: https://sg.run/PYBz + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-disallow-doctype-decl-missing.documentbuilderfactory-disallow-doctype-decl-missing + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: "$FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n" + - pattern: "$FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\", false);\n...\n$FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false);\n" + - pattern: "$FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n...\n$FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false);\n" + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\"\ + ,\n true);\n ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false);\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n\ + \ ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\"\ + , false);\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\",false);\n\ + \ ...\n }\n ...\n}\n" + - pattern: $M($X) + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern: $FACTORY.newDocumentBuilder(); + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: "$FACTORY = DocumentBuilderFactory.newInstance();\n" + - patterns: + - pattern: $FACTORY + - pattern-inside: "class $C {\n ...\n $V $FACTORY = DocumentBuilderFactory.newInstance();\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = DocumentBuilderFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n ...\n }\n ...\n\ + }\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = DocumentBuilderFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n ...\n $FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false);\n ...\n }\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = DocumentBuilderFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\", false);\n ...\n $FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false);\n ...\n }\n ...\n}\n" + severity: ERROR +- fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", false); + id: + java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + languages: + - java + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this + by setting the feature "http://xml.org/sax/features/external-general-entities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + semgrep.dev: + rule: + origin: community + r_id: 18246 + rule_id: 9AUJ6r + rv_id: 1263059 + url: + https://semgrep.dev/playground/r/qkTR7Lk/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + version_id: qkTR7Lk + shortlink: https://sg.run/JgPy + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-general-entities-true.documentbuilderfactory-external-general-entities-true + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-general-entities", true); + severity: ERROR +- fix: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", false); + id: + java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + languages: + - java + message: External entities are allowed for $DBFACTORY. This is vulnerable to XML external entity attacks. Disable this + by setting the feature "http://xml.org/sax/features/external-parameter-entities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + semgrep.dev: + rule: + origin: community + r_id: 18247 + rule_id: yyUNeo + rv_id: 1263060 + url: + https://semgrep.dev/playground/r/l4TJRoL/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + version_id: l4TJRoL + shortlink: https://sg.run/5Lv0 + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.documentbuilderfactory-external-parameter-entities-true.documentbuilderfactory-external-parameter-entities-true + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + pattern: $DBFACTORY.setFeature("http://xml.org/sax/features/external-parameter-entities", true); + severity: ERROR +- fix: "$FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n$FACTORY.newSAXParser();\n" + id: + java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + languages: + - java + message: DOCTYPE declarations are enabled for this SAXParserFactory. This is vulnerable to XML external entity + attacks. Disable this by setting the feature `http://apache.org/xml/features/disallow-doctype-decl` to true. + Alternatively, allow DOCTYPE declarations and only prohibit external entities declarations. This can be done by + setting the features `http://xml.org/sax/features/external-general-entities` and + `http://xml.org/sax/features/external-parameter-entities` to false. NOTE - The previous links are not meant to be + clicked. They are the literal config key values that are supposed to be used to disable these features. For more + information, see https://semgrep.dev/docs/cheat-sheets/java-xxe/#3a-documentbuilderfactory. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + semgrep.dev: + rule: + origin: community + r_id: 59048 + rule_id: j2Udpk + rv_id: 1263061 + url: + https://semgrep.dev/playground/r/YDTZeko/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + version_id: YDTZeko + shortlink: https://sg.run/Gj32 + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.saxparserfactory-disallow-doctype-decl-missing.saxparserfactory-disallow-doctype-decl-missing + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: "$FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n" + - pattern: "$FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\", false);\n...\n$FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false);\n" + - pattern: "$FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n...\n$FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false);\n" + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\"\ + ,\n true);\n ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false);\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n\ + \ ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\"\ + , false);\n ...\n $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\",false);\n\ + \ ...\n }\n ...\n}\n" + - pattern: $M($X) + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern: $FACTORY.newSAXParser(); + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: "$FACTORY = SAXParserFactory.newInstance();\n" + - patterns: + - pattern: $FACTORY + - pattern-inside: "class $C {\n ...\n $V $FACTORY = SAXParserFactory.newInstance();\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = SAXParserFactory.newInstance();\n static {\n ...\n \ + \ $FACTORY.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true);\n ...\n }\n ...\n\ + }\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = SAXParserFactory.newInstance();\n static {\n ...\n \ + \ $FACTORY.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false);\n ...\n $FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false);\n ...\n }\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = SAXParserFactory.newInstance();\n static {\n ...\n \ + \ $FACTORY.setFeature(\"http://xml.org/sax/features/external-general-entities\", false);\n ...\n $FACTORY.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false);\n ...\n }\n ...\n}\n" + severity: ERROR +- fix: "$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\"); $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, + \"\");\n$FACTORY.newTransformer(...);\n" + id: java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + languages: + - java + message: DOCTYPE declarations are enabled for this TransformerFactory. This is vulnerable to XML external entity + attacks. Disable this by setting the attributes "accessExternalDTD" and "accessExternalStylesheet" to "". + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://blog.sonarsource.com/secure-xml-processor + - https://xerces.apache.org/xerces2-j/features.html + semgrep.dev: + rule: + origin: community + r_id: 59622 + rule_id: v8UeQ1 + rv_id: 1263062 + url: + https://semgrep.dev/playground/r/6xT29GK/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + version_id: 6xT29GK + shortlink: https://sg.run/1wyQ + source: + https://semgrep.dev/r/java.lang.security.audit.xxe.transformerfactory-dtds-not-disabled.transformerfactory-dtds-not-disabled + subcategory: + - vuln + technology: + - java + - xml + vulnerability_class: + - XML Injection + mode: taint + pattern-sanitizers: + - by-side-effect: true + pattern-either: + - patterns: + - pattern-either: + - pattern: "$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, \"\"); ...\n$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, + \"\");\n" + - pattern: "$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\");\n...\n$FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, + \"\");\n" + - pattern: "$FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\", \"\"); ...\n$FACTORY.setAttribute(\"=~/.*accessExternalDTD.*/\"\ + , \"\");\n" + - pattern: "$FACTORY.setAttribute(\"=~/.*accessExternalDTD.*/\", \"\");\n...\n$FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\"\ + , \"\");\n" + - focus-metavariable: $FACTORY + - patterns: + - pattern-either: + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, + \"\");\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\");\n ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, + \"\");\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, \"\");\n ...\n }\n ...\n\ + }\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\"\ + , \"\");\n ...\n $FACTORY.setAttribute(\"=~/.*accessExternalDTD.*/\", \"\");\n ...\n }\n ...\n}\n" + - pattern-inside: "class $C {\n ...\n $T $M(...) {\n ...\n $FACTORY.setAttribute(\"=~/.*accessExternalDTD.*/\"\ + , \"\");\n ...\n $FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\", \"\");\n ...\n }\n ...\n\ + }\n" + - pattern: $M($X) + - focus-metavariable: $X + pattern-sinks: + - patterns: + - pattern: $FACTORY.newTransformer(...); + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: "$FACTORY = TransformerFactory.newInstance();\n" + - patterns: + - pattern: $FACTORY + - pattern-inside: "class $C {\n ...\n $V $FACTORY = TransformerFactory.newInstance();\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = TransformerFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, \"\");\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, + \"\");\n ...\n }\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = TransformerFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, \"\");\n ...\n $FACTORY.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, + \"\");\n ...\n }\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = TransformerFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setAttribute(\"=~/.*accessExternalDTD.*/\", \"\");\n ...\n $FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\"\ + , \"\");\n ...\n }\n ...\n}\n" + - pattern-not-inside: "class $C {\n ...\n $V $FACTORY = TransformerFactory.newInstance();\n static {\n ...\n\ + \ $FACTORY.setAttribute(\"=~/.*accessExternalStylesheet.*/\", \"\");\n ...\n $FACTORY.setAttribute(\"\ + =~/.*accessExternalDTD.*/\", \"\");\n ...\n }\n ...\n}\n" + severity: ERROR +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + languages: + - java + message: Detected a potential path traversal. A malicious actor could control the location of this file, to include + going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths + are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.owasp.org/index.php/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9160 + rule_id: NbUk7X + rv_id: 1263064 + url: + https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + version_id: zyTb2rq + shortlink: https://sg.run/oxXN + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.io.File $FILE) = ...\n" + - pattern: "(java.io.FileOutputStream $FOS) = ...\n" + - pattern: "new java.io.FileInputStream(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ)\n" + - patterns: + - pattern-inside: "(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);\n...\nfor (javax.servlet.http.Cookie + $COOKIE: $COOKIES) {\n ...\n}\n" + - pattern: "$COOKIE.getValue(...)\n" + - patterns: + - pattern-inside: "$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...);\n...\n" + - pattern: "$PARAM = $VALS[$INDEX];\n" + severity: ERROR +- id: java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + languages: + - java + message: JMS Object messages depend on Java Serialization for marshalling/unmarshalling of the message payload when + ObjectMessage.getObject() is called. Deserialization of untrusted data can lead to security flaws; a remote attacker + could via a crafted JMS ObjectMessage to execute arbitrary code with the permissions of the application + listening/consuming JMS Messages. In this case, the JMS MessageListener consume an ObjectMessage type received + inside the onMessage method, which may lead to arbitrary code execution when calling the $Y.getObject method. + metadata: + asvs: + control_id: 5.5.3 Insecue Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://www.blackhat.com/docs/us-16/materials/us-16-Kaiser-Pwning-Your-Java-Messaging-With-Deserialization-Vulnerabilities-wp.pdf + semgrep.dev: + rule: + origin: community + r_id: 9161 + rule_id: kxUk12 + rv_id: 1263065 + url: + https://semgrep.dev/playground/r/pZT03A1/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + version_id: pZT03A1 + shortlink: https://sg.run/zvO1 + source: https://semgrep.dev/r/java.lang.security.insecure-jms-deserialization.insecure-jms-deserialization + subcategory: + - vuln + technology: + - java + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "public class $JMS_LISTENER implements MessageListener {\n ...\n public void onMessage(Message $JMS_MSG) + {\n ...\n }\n}\n" + - pattern-either: + - pattern-inside: $X = $Y.getObject(...); + - pattern-inside: $X = ($Z) $Y.getObject(...); + severity: WARNING +- id: java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + languages: + - java + message: When using Jackson to marshall/unmarshall JSON to Java objects, enabling default typing is dangerous and can + lead to RCE. If an attacker can control `$JSON` it might be possible to provide a malicious JSON which can be used + to exploit unsecure deserialization. In order to prevent this issue, avoid to enable default typing (globally or by + using "Per-class" annotations) and avoid using `Object` and other dangerous types for member variable declaration + which creating classes for Jackson based deserialization. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A8:2017 Insecure Deserialization + - A8:2021 Software and Data Integrity Failures + references: + - https://swapneildash.medium.com/understanding-insecure-implementation-of-jackson-deserialization-7b3d409d2038 + - https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 + - https://adamcaudill.com/2017/10/04/exploiting-jackson-rce-cve-2017-7525/ + semgrep.dev: + rule: + origin: community + r_id: 56948 + rule_id: QrUD20 + rv_id: 945724 + url: + https://semgrep.dev/playground/r/2KTYbA9/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + version_id: 2KTYbA9 + shortlink: https://sg.run/GDop + source: https://semgrep.dev/r/java.lang.security.jackson-unsafe-deserialization.jackson-unsafe-deserialization + subcategory: + - audit + technology: + - jackson + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-either: + - patterns: + - pattern-inside: "ObjectMapper $OM = new ObjectMapper(...);\n...\n" + - pattern-inside: "$OM.enableDefaultTyping();\n...\n" + - pattern: $OM.readValue($JSON, ...); + - patterns: + - pattern-inside: "class $CLASS {\n ...\n @JsonTypeInfo(use = Id.CLASS,...)\n $TYPE $VAR;\n ...\n}\n" + - metavariable-regex: + metavariable: $TYPE + regex: (Object|Serializable|Comparable) + - pattern: $OM.readValue($JSON, $CLASS.class); + - patterns: + - pattern-inside: "class $CLASS {\n ...\n ObjectMapper $OM;\n ...\n $INITMETHODTYPE $INITMETHOD(...) {\n ...\n\ + \ $OM = new ObjectMapper();\n ...\n $OM.enableDefaultTyping();\n ...\n }\n ...\n}\n" + - pattern-inside: "$METHODTYPE $METHOD(...) {\n ... \n}\n" + - pattern: $OM.readValue($JSON, ...); + severity: WARNING +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + languages: + - java + message: "Cross-site scripting detected in HttpServletResponse writer with variable '$VAR'. User input was detected going + directly from the HttpServletRequest into output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + 'Encode.forHtml($VAR)'." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9162 + rule_id: wdUJOk + rv_id: 1263066 + url: + https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + version_id: 2KTv2EG + shortlink: https://sg.run/pxjN + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: "$WRITER = $RESP.getWriter(...);\n...\n$WRITER.write(..., $VAR, ...);\n" + severity: ERROR +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + languages: + - java + message: XML external entities are not explicitly disabled for this XMLInputFactory. This could be vulnerable to XML + external entity vulnerabilities. Explicitly disable external entities by setting + "javax.xml.stream.isSupportingExternalEntities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + semgrep.dev: + rule: + origin: community + r_id: 9164 + rule_id: OrU35O + rv_id: 1263069 + url: + https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + version_id: 1QTypQZ + shortlink: https://sg.run/XBwA + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + subcategory: + - vuln + technology: + - java + vulnerability_class: + - XML Injection + patterns: + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(\"javax.xml.stream.isSupportingExternalEntities\"\ + , false);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + false);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(\"javax.xml.stream.isSupportingExternalEntities\"\ + , Boolean.FALSE);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + Boolean.FALSE);\n ...\n}\n" + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + severity: WARNING +- id: java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + languages: + - yaml + message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints such as /actuator/env, + /actuator/logfile, /actuator/heapdump and others. Unless you have Spring Security enabled or another means to + protect these endpoints, this functionality is available without authentication, causing a severe security risk. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + semgrep.dev: + rule: + origin: community + r_id: 29422 + rule_id: eqUerQ + rv_id: 1263076 + url: + https://semgrep.dev/playground/r/w8TRo5n/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + version_id: w8TRo5n + shortlink: https://sg.run/1Bzw + source: + https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled-yaml.spring-actuator-fully-enabled-yaml + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-inside: "management:\n ...\n endpoints:\n ...\n web:\n ...\n exposure:\n ...\n" + - pattern: "include: \"*\"\n" + severity: WARNING +- id: java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + languages: + - generic + message: Spring Boot Actuator is fully enabled. This exposes sensitive endpoints such as /actuator/env, + /actuator/logfile, /actuator/heapdump and others. Unless you have Spring Security enabled or another means to + protect these endpoints, this functionality is available without authentication, causing a significant security + risk. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + semgrep.dev: + rule: + origin: community + r_id: 10439 + rule_id: EwU4vg + rv_id: 1263077 + url: + https://semgrep.dev/playground/r/xyTjzwp/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + version_id: xyTjzwp + shortlink: https://sg.run/L0vY + source: https://semgrep.dev/r/java.spring.security.audit.spring-actuator-fully-enabled.spring-actuator-fully-enabled + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Mishandled Sensitive Information + paths: + include: + - '*properties' + pattern: management.endpoints.web.exposure.include=* + severity: ERROR +- id: + java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + languages: + - yaml + message: Spring Boot Actuator "$ACTUATOR" is enabled. Depending on the actuator, this can pose a significant security + risk. Please double-check if the actuator is needed and properly secured. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + semgrep.dev: + rule: + origin: community + r_id: 32290 + rule_id: kxUWpX + rv_id: 1263078 + url: + https://semgrep.dev/playground/r/O9TpxBp/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + version_id: O9TpxBp + shortlink: https://sg.run/JzKQ + source: + https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled-yaml.spring-actuator-dangerous-endpoints-enabled-yaml + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-inside: "management:\n ...\n endpoints:\n ...\n web:\n ...\n exposure:\n ...\n \ + \ include:\n ...\n" + - pattern: "include: [..., $ACTUATOR, ...]\n" + - metavariable-comparison: + comparison: not str($ACTUATOR) in ["health","*"] + metavariable: $ACTUATOR + severity: WARNING +- id: java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + languages: + - generic + message: Spring Boot Actuators "$...ACTUATORS" are enabled. Depending on the actuators, this can pose a significant + security risk. Please double-check if the actuators are needed and properly secured. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.spring.io/spring-boot/docs/current/reference/html/production-ready-features.html#production-ready-endpoints-exposing-endpoints + - https://medium.com/walmartglobaltech/perils-of-spring-boot-actuators-misconfiguration-185c43a0f785 + - https://blog.maass.xyz/spring-actuator-security-part-1-stealing-secrets-using-spring-actuators + semgrep.dev: + rule: + origin: community + r_id: 32291 + rule_id: wdUWrZ + rv_id: 1263079 + url: + https://semgrep.dev/playground/r/e1Tyjqe/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + version_id: e1Tyjqe + shortlink: https://sg.run/5g23 + source: + https://semgrep.dev/r/java.spring.security.audit.spring-actuator-non-health-enabled.spring-actuator-dangerous-endpoints-enabled + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Mishandled Sensitive Information + options: + generic_ellipsis_max_span: 0 + patterns: + - pattern: management.endpoints.web.exposure.include=$...ACTUATORS + - metavariable-comparison: + comparison: not str($...ACTUATORS) in ["health","*"] + metavariable: $...ACTUATORS + severity: WARNING +- id: java.spring.security.audit.spring-sqli.spring-sqli + languages: + - java + message: Detected a string argument from a public method contract in a raw SQL statement. This could lead to SQL + injection if variables in the SQL statement are not properly sanitized. Use a prepared statements + (java.sql.PreparedStatement) instead. You can obtain a PreparedStatement using 'connection.prepareStatement'. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9222 + rule_id: eqU8N2 + rv_id: 1263082 + url: https://semgrep.dev/playground/r/ZRTKAWW/java.spring.security.audit.spring-sqli.spring-sqli + version_id: ZRTKAWW + shortlink: https://sg.run/1Z3x + source: https://semgrep.dev/r/java.spring.security.audit.spring-sqli.spring-sqli + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - SQL Injection + mode: taint + options: + taint_assume_safe_booleans: true + taint_assume_safe_numbers: true + pattern-sanitizers: + - not_conflicting: true + pattern-either: + - patterns: + - focus-metavariable: $A + - pattern-inside: "new $TYPE(...,$A,...);\n" + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - focus-metavariable: $A + - pattern: "new PreparedStatementCreatorFactory($A,...);\n" + - patterns: + - focus-metavariable: $A + - pattern: "(JdbcTemplate $T).$M($A,...)\n" + - patterns: + - pattern: (String $A) + - pattern-inside: "(JdbcTemplate $T).batchUpdate(...)\n" + - patterns: + - focus-metavariable: $A + - pattern: "NamedParameterBatchUpdateUtils.$M($A,...)\n" + - patterns: + - focus-metavariable: $A + - pattern: "BatchUpdateUtils.$M($A,...)\n" + pattern-sources: + - patterns: + - pattern: $ARG + - pattern-inside: "public $T $M (..., String $ARG,...){...}\n" + severity: WARNING +- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + languages: + - java + message: Application redirects a user to a destination URL specified by a user supplied parameter that is not + validated. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9223 + rule_id: v8Un7w + rv_id: 1263083 + url: + https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + version_id: nWT2Lk0 + shortlink: https://sg.run/9oXz + source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Open Redirect + pattern-either: + - pattern: "$X $METHOD(...,String $URL,...) {\n return \"redirect:\" + $URL;\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n String $REDIR = \"redirect:\" + $URL;\n ...\n return $REDIR;\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n new ModelAndView(\"redirect:\" + $URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n String $REDIR = \"redirect:\" + $URL;\n ...\n new ModelAndView($REDIR);\n\ + \ ...\n}" + severity: WARNING +- id: java.spring.security.injection.tainted-file-path.tainted-file-path + languages: + - java + message: Detected user input controlling a file path. An attacker could control the location of this file, to include + going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths + are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-23: Relative Path Traversal' + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 22074 + rule_id: lBUxok + rv_id: 1263084 + url: https://semgrep.dev/playground/r/ExTEx6Y/java.spring.security.injection.tainted-file-path.tainted-file-path + version_id: ExTEx6Y + shortlink: https://sg.run/x9o0 + source: https://semgrep.dev/r/java.spring.security.injection.tainted-file-path.tainted-file-path + subcategory: + - vuln + technology: + - java + - spring + vulnerability_class: + - Path Traversal + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new File(...) + - pattern: new java.io.File(...) + - pattern: new FileReader(...) + - pattern: new java.io.FileReader(...) + - pattern: new FileInputStream(...) + - pattern: new java.io.FileInputStream(...) + - pattern: (Paths $PATHS).get(...) + - patterns: + - pattern: "$CLASS.$FUNC(...)\n" + - metavariable-regex: + metavariable: $FUNC + regex: ^(getResourceAsStream|getResource)$ + - patterns: + - pattern-either: + - pattern: new ClassPathResource($FILE, ...) + - pattern: ResourceUtils.getFile($FILE, ...) + - pattern: new FileOutputStream($FILE, ...) + - pattern: new java.io.FileOutputStream($FILE, ...) + - pattern: new StreamSource($FILE, ...) + - pattern: new javax.xml.transform.StreamSource($FILE, ...) + - pattern: FileUtils.openOutputStream($FILE, ...) + - focus-metavariable: $FILE + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {\n ...\n}\n" + - pattern-inside: "$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {\n ...\n}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + severity: ERROR +- id: java.spring.security.injection.tainted-html-string.tainted-html-string + languages: + - java + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. You can use the OWASP ESAPI encoder if you must render user data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22075 + rule_id: YGUvkL + rv_id: 1409395 + url: + https://semgrep.dev/playground/r/3ZT2598/java.spring.security.injection.tainted-html-string.tainted-html-string + version_id: 3ZT2598 + shortlink: https://sg.run/ObdR + source: https://semgrep.dev/r/java.spring.security.injection.tainted-html-string.tainted-html-string + subcategory: + - vuln + technology: + - java + - spring + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-propagators: + - from: $...TAINTED + pattern: (StringBuilder $SB).append($...TAINTED) + to: $SB + - from: $...TAINTED + pattern: $VAR += $...TAINTED + to: $VAR + pattern-sanitizers: + - pattern-either: + - pattern: Encode.forHtml(...) + - pattern: (PolicyFactory $POLICY).sanitize(...) + - pattern: (AntiSamy $AS).scan(...) + - pattern: JSoup.clean(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: new ResponseEntity<>($PAYLOAD, ...) + - pattern: new ResponseEntity<$ERROR>($PAYLOAD, ...) + - pattern: ResponseEntity. ... .body($PAYLOAD) + - patterns: + - pattern: "ResponseEntity.$RESPFUNC($PAYLOAD). ...\n" + - metavariable-regex: + metavariable: $RESPFUNC + regex: ^(ok|of)$ + - focus-metavariable: $PAYLOAD + requires: CONCAT + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern-inside: "$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {\n ...\n}\n" + - pattern-inside: "$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {\n ...\n}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + - by-side-effect: true + label: CONCAT + patterns: + - pattern-either: + - pattern: "\"$HTMLSTR\" + ...\n" + - pattern: "\"$HTMLSTR\".concat(...)\n" + - patterns: + - pattern-inside: "StringBuilder $SB = new StringBuilder(\"$HTMLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$HTMLSTR\";\n...\n" + - pattern: $VAR += ... + - pattern: String.format("$HTMLSTR", ...) + - patterns: + - pattern-inside: "String $VAR = \"$HTMLSTR\";\n...\n" + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $HTMLSTR + regex: ^<\w+ + requires: INPUT + severity: ERROR +- id: java.spring.security.injection.tainted-sql-string.tainted-sql-string + languages: + - java + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + semgrep.dev: + rule: + origin: community + r_id: 14767 + rule_id: 10UdRR + rv_id: 1409396 + url: + https://semgrep.dev/playground/r/44TbKvr/java.spring.security.injection.tainted-sql-string.tainted-sql-string + version_id: 44TbKvr + shortlink: https://sg.run/9rzz + source: https://semgrep.dev/r/java.spring.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + taint_assume_safe_booleans: true + taint_assume_safe_numbers: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\".concat(...)\n" + - patterns: + - pattern-inside: "StringBuilder $SB = new StringBuilder(\"$SQLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\";\n...\n" + - pattern: $VAR += ... + - pattern: String.format("$SQLSTR", ...) + - patterns: + - pattern-inside: "String $VAR = \"$SQLSTR\";\n...\n" + - pattern: String.format($VAR, ...) + - pattern-not-inside: System.out.println(...) + - pattern-not-inside: $LOG.info(...) + - pattern-not-inside: $LOG.warn(...) + - pattern-not-inside: $LOG.warning(...) + - pattern-not-inside: $LOG.debug(...) + - pattern-not-inside: $LOG.debugging(...) + - pattern-not-inside: $LOG.error(...) + - pattern-not-inside: new Exception(...) + - pattern-not-inside: throw ...; + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {\n ...\n}\n" + - pattern-inside: "$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {\n ...\n}\n" + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue) + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - focus-metavariable: $SOURCE + severity: ERROR +- id: java.spring.security.injection.tainted-system-command.tainted-system-command + languages: + - java + message: "Detected user input entering a method which executes a system command. This could result in a command injection + vulnerability, which allows an attacker to inject an arbitrary system command onto the server. The attacker could download + malware onto or steal data from the server. Instead, use ProcessBuilder, separating the command into individual arguments, + like this: `new ProcessBuilder(\"ls\", \"-al\", targetDirectory)`. Further, make sure you hardcode or allowlist the actual + command so that attackers can't run arbitrary commands." + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.stackhawk.com/blog/command-injection-java/ + - https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html + - https://github.com/github/codeql/blob/main/java/ql/src/Security/CWE/CWE-078/ExecUnescaped.java + semgrep.dev: + rule: + origin: community + r_id: 22076 + rule_id: 6JUxGN + rv_id: 1263087 + url: + https://semgrep.dev/playground/r/8KT5rnP/java.spring.security.injection.tainted-system-command.tainted-system-command + version_id: 8KT5rnP + shortlink: https://sg.run/epY0 + source: https://semgrep.dev/r/java.spring.security.injection.tainted-system-command.tainted-system-command + subcategory: + - vuln + technology: + - java + - spring + vulnerability_class: + - Command Injection + mode: taint + pattern-propagators: + - from: $INPUT + label: CONCAT + pattern: (StringBuilder $STRB).append($INPUT) + requires: INPUT + to: $STRB + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(Process $P) = new Process(...);\n" + - pattern: "(ProcessBuilder $PB).command(...);\n" + - patterns: + - pattern-either: + - pattern: "(Runtime $R).$EXEC(...);\n" + - pattern: "Runtime.getRuntime(...).$EXEC(...);\n" + - metavariable-regex: + metavariable: $EXEC + regex: (exec|loadLibrary|load) + - patterns: + - pattern: "(ProcessBuilder $PB).command(...).$ADD(...);\n" + - metavariable-regex: + metavariable: $ADD + regex: (add|addAll) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$BUILDER = new ProcessBuilder(...);\n...\n" + - pattern: $BUILDER.start(...) + - pattern: "new ProcessBuilder(...). ... .start(...);\n" + requires: CONCAT + pattern-sources: + - label: INPUT + patterns: + - pattern-either: + - pattern-inside: "$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {\n ...\n}\n" + - pattern-inside: "$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {\n ...\n}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + - label: CONCAT + patterns: + - pattern-either: + - pattern: $X + $SOURCE + - pattern: $SOURCE + $Y + - pattern: String.format("...", ..., $SOURCE, ...) + - pattern: String.join("...", ..., $SOURCE, ...) + - pattern: (String $STR).concat($SOURCE) + - pattern: $SOURCE.concat(...) + - pattern: $X += $SOURCE + - pattern: $SOURCE += $X + requires: INPUT + severity: ERROR +- id: java.spring.security.injection.tainted-url-host.tainted-url-host + languages: + - java + message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send + data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with + this request. They could also probe internal servers or other resources that the server running this code can + access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an + allowlist for approved hosts, hardcode the correct host, or ensure that the user data can only affect the path or + parameters. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22077 + rule_id: oqUZo8 + rv_id: 1263088 + url: https://semgrep.dev/playground/r/gETB708/java.spring.security.injection.tainted-url-host.tainted-url-host + version_id: gETB708 + shortlink: https://sg.run/vkYn + source: https://semgrep.dev/r/java.spring.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - java + - spring + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + interfile: true + pattern-sinks: + - pattern-either: + - pattern: new URL($ONEARG) + - patterns: + - pattern-either: + - pattern: "\"$URLSTR\" + ...\n" + - pattern: "\"$URLSTR\".concat(...)\n" + - patterns: + - pattern-inside: "StringBuilder $SB = new StringBuilder(\"$URLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$URLSTR\";\n...\n" + - pattern: $VAR += ... + - patterns: + - pattern: String.format("$URLSTR", ...) + - pattern-not: String.format("$URLSTR", "...", ...) + - patterns: + - pattern-inside: "String $VAR = \"$URLSTR\";\n...\n" + - pattern: String.format($VAR, ...) + - metavariable-regex: + metavariable: $URLSTR + regex: http(s?)://%(v|s|q).* + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "$METHODNAME(..., @$REQ(...) $TYPE $SOURCE,...) {\n ...\n}\n" + - pattern-inside: "$METHODNAME(..., @$REQ $TYPE $SOURCE,...) {\n ...\n}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(?!(Integer|Long|Float|Double|Char|Boolean|int|long|float|double|char|boolean)) + - metavariable-regex: + metavariable: $REQ + regex: (RequestBody|PathVariable|RequestParam|RequestHeader|CookieValue|ModelAttribute) + - focus-metavariable: $SOURCE + severity: ERROR +- id: javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + languages: + - javascript + - typescript + message: Use of angular.element can lead to XSS if user-input is treated as part of the HTML element within `$SINK`. + It is recommended to contextually output encode user-input, before inserting into `$SINK`. If the HTML needs to be + preserved it is recommended to sanitize the input using $sce.getTrustedHTML or $sanitize. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/function/angular.element + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 21503 + rule_id: GdUP71 + rv_id: 1263091 + url: + https://semgrep.dev/playground/r/44TEj8L/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + version_id: 44TEj8L + shortlink: https://sg.run/5AQ0 + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-element-taint.detect-angular-element-taint + subcategory: + - vuln + technology: + - angularjs + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $sce.getTrustedHtml(...) + - pattern: $sanitize(...) + - pattern: DOMPurify.sanitize(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "angular.element(...). ... .$SINK($QUERY)\n" + - pattern-inside: "$ANGULAR = angular.element(...)\n...\n$ANGULAR. ... .$SINK($QUERY)\n" + - metavariable-regex: + metavariable: $SINK + regex: ^(after|append|html|prepend|replaceWith|wrap)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern: window.location.search + - pattern: window.document.location.search + - pattern: document.location.search + - pattern: location.search + - pattern: $location.search(...) + - patterns: + - pattern-either: + - pattern: $DECODE(<... location.hash ...>) + - pattern: $DECODE(<... window.location.hash ...>) + - pattern: $DECODE(<... document.location.hash ...>) + - pattern: $DECODE(<... location.href ...>) + - pattern: $DECODE(<... window.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.URL ...>) + - pattern: $DECODE(<... window.document.URL ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... document.location.href ...>) + - pattern: $DECODE(<... $location.absUrl() ...>) + - pattern: $DECODE(<... $location.url() ...>) + - pattern: $DECODE(<... $location.hash() ...>) + - metavariable-regex: + metavariable: $DECODE + regex: ^(unescape|decodeURI|decodeURIComponent)$ + - patterns: + - pattern-inside: $http.$METHOD(...).$CONTINUE(function $FUNC($RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|delete|head|jsonp|post|put|patch) + - pattern: $RES.data + severity: WARNING +- id: javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + languages: + - javascript + - typescript + message: $sceProvider is set to false. Disabling Strict Contextual escaping (SCE) in an AngularJS application could + provide additional attack surface for XSS vulnerabilities. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 9227 + rule_id: EwU20Z + rv_id: 1263094 + url: + https://semgrep.dev/playground/r/5PTo1EW/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + version_id: 5PTo1EW + shortlink: https://sg.run/N4DG + source: https://semgrep.dev/r/javascript.angular.security.detect-angular-sce-disabled.detect-angular-sce-disabled + subcategory: + - vuln + technology: + - angular + vulnerability_class: + - Cross-Site-Scripting (XSS) + pattern: "$sceProvider.enabled(false);\n" + severity: ERROR +- id: javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + languages: + - javascript + - typescript + message: The use of $sce.trustAs can be dangerous if unsanitized user input flows through this API. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.angularjs.org/api/ng/service/$sce + - https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20170727_AngularJS.pdf + semgrep.dev: + rule: + origin: community + r_id: 9231 + rule_id: gxU1QX + rv_id: 1263098 + url: + https://semgrep.dev/playground/r/BjTkZv0/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + version_id: BjTkZv0 + shortlink: https://sg.run/OPW2 + source: + https://semgrep.dev/r/javascript.angular.security.detect-angular-trust-as-method.detect-angular-trust-as-method + subcategory: + - vuln + technology: + - angular + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - pattern: $sce.trustAs(...) + - pattern: $sce.trustAsHtml(...) + pattern-sources: + - patterns: + - pattern-inside: "app.controller(..., function($scope,$sce) {\n...\n});\n" + - pattern: $scope.$X + severity: WARNING +- id: javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + languages: + - javascript + - typescript + message: Prefer Argon2id where possible. Per RFC9016, section 4 IETF recommends selecting Argon2id unless you can + guarantee an adversary has no direct access to the computing environment. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-916: Use of Password Hash With Insufficient Computational Effort' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html + - https://eprint.iacr.org/2016/759.pdf + - https://www.cs.tau.ac.il/~tromer/papers/cache-joc-20090619.pdf + - https://datatracker.ietf.org/doc/html/rfc9106#section-4 + semgrep.dev: + rule: + origin: community + r_id: 20150 + rule_id: DbU2X8 + rv_id: 1263103 + url: + https://semgrep.dev/playground/r/qkTR7Jk/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + version_id: qkTR7Jk + shortlink: https://sg.run/ALq4 + source: https://semgrep.dev/r/javascript.argon2.security.unsafe-argon2-config.unsafe-argon2-config + subcategory: + - vuln + technology: + - argon2 + - cryptography + vulnerability_class: + - Insecure Hashing Algorithm + mode: taint + pattern-sanitizers: + - patterns: + - pattern: '{type: $ARGON.argon2id}' + pattern-sinks: + - patterns: + - pattern: "$Y\n" + - pattern-inside: "$ARGON.hash(...,$Y)\n" + pattern-sources: + - patterns: + - pattern-inside: "$ARGON = require('argon2');\n...\n" + - pattern: "{type: ...}\n" + severity: WARNING +- id: javascript.aws-lambda.security.detect-child-process.detect-child-process + languages: + - javascript + - typescript + message: Allowing spawning arbitrary programs or running shell processes with arbitrary arguments may end up in a + command injection vulnerability. Try to avoid non-literal values for the command string. If it is not possible, then + do not let running arbitrary commands, use a white list for inputs. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18248 + rule_id: r6UDNQ + rv_id: 1263105 + url: + https://semgrep.dev/playground/r/YDTZe4o/javascript.aws-lambda.security.detect-child-process.detect-child-process + version_id: YDTZe4o + shortlink: https://sg.run/Ggoq + source: https://semgrep.dev/r/javascript.aws-lambda.security.detect-child-process.detect-child-process + subcategory: + - vuln + technology: + - javascript + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: exec($CMD,...) + - pattern: execSync($CMD,...) + - pattern: spawn($CMD,...) + - pattern: spawnSync($CMD,...) + - pattern: $CP.exec($CMD,...) + - pattern: $CP.execSync($CMD,...) + - pattern: $CP.spawn($CMD,...) + - pattern: $CP.spawnSync($CMD,...) + - pattern-either: + - pattern-inside: "require('child_process')\n...\n" + - pattern-inside: "import 'child_process'\n...\n" + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + languages: + - javascript + - typescript + message: Detected DynamoDB query params that are tainted by `$EVENT` object. This could lead to NoSQL injection if the + variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from + `$EVENT` directly to DynamoDB client. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 21320 + rule_id: 0oU1xk + rv_id: 945766 + url: + https://semgrep.dev/playground/r/GxTP7gN/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + version_id: GxTP7gN + shortlink: https://sg.run/X1e4 + source: https://semgrep.dev/r/javascript.aws-lambda.security.dynamodb-request-object.dynamodb-request-object + subcategory: + - vuln + technology: + - javascript + - aws-lambda + - dynamodb + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "{...}\n" + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern: "$DC.$METHOD($SINK, ...)\n" + - metavariable-regex: + metavariable: $METHOD + regex: + (query|send|scan|delete|put|transactWrite|update|batchExecuteStatement|executeStatement|executeTransaction|transactWriteItems) + - pattern-either: + - pattern-inside: "$DC = new $AWS.DocumentClient(...);\n...\n" + - pattern-inside: "$DC = new $AWS.DynamoDB(...);\n...\n" + - pattern-inside: "$DC = new DynamoDBClient(...);\n...\n" + - pattern-inside: "$DC = DynamoDBDocumentClient.from(...);\n...\n" + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.aws-lambda.security.knex-sqli.knex-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `knex.raw('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + semgrep.dev: + rule: + origin: community + r_id: 18249 + rule_id: bwUBlj + rv_id: 1263106 + url: https://semgrep.dev/playground/r/JdTzxKg/javascript.aws-lambda.security.knex-sqli.knex-sqli + version_id: JdTzxKg + shortlink: https://sg.run/RgWq + source: https://semgrep.dev/r/javascript.aws-lambda.security.knex-sqli.knex-sqli + subcategory: + - vuln + technology: + - aws-lambda + - knex + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $KNEX.fromRaw($QUERY, ...) + - pattern: $KNEX.whereRaw($QUERY, ...) + - pattern: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: "require('knex')\n...\n" + - pattern-inside: "import 'knex'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.npmjs.com/package/mysql2 + semgrep.dev: + rule: + origin: community + r_id: 18250 + rule_id: NbUBJ2 + rv_id: 1263107 + url: https://semgrep.dev/playground/r/5PTo1En/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + version_id: 5PTo1En + shortlink: https://sg.run/A502 + source: https://semgrep.dev/r/javascript.aws-lambda.security.mysql-sqli.mysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - mysql + - mysql2 + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $POOL.query($QUERY, ...) + - pattern: $POOL.execute($QUERY, ...) + - pattern-either: + - pattern-inside: "require('mysql')\n...\n" + - pattern-inside: "require('mysql2')\n...\n" + - pattern-inside: "require('mysql2/promise')\n...\n" + - pattern-inside: "import 'mysql'\n...\n" + - pattern-inside: "import 'mysql2'\n...\n" + - pattern-inside: "import 'mysql2/promise'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.pg-sqli.pg-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `connection.query('SELECT $1 from table', [userinput])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://node-postgres.com/features/queries + semgrep.dev: + rule: + origin: community + r_id: 18251 + rule_id: kxU25P + rv_id: 1263108 + url: https://semgrep.dev/playground/r/GxTkeJL/javascript.aws-lambda.security.pg-sqli.pg-sqli + version_id: GxTkeJL + shortlink: https://sg.run/BGKA + source: https://semgrep.dev/r/javascript.aws-lambda.security.pg-sqli.pg-sqli + subcategory: + - vuln + technology: + - aws-lambda + - postgres + - pg + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: "require('pg')\n...\n" + - pattern-inside: "import 'pg'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$EVENT` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `sequelize.query('SELECT * FROM projects WHERE status = ?', { replacements: + ['active'], type: QueryTypes.SELECT });`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sequelize.org/master/manual/raw-queries.html + semgrep.dev: + rule: + origin: community + r_id: 18252 + rule_id: wdUA5o + rv_id: 1263109 + url: https://semgrep.dev/playground/r/RGT0LrD/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + version_id: RGT0LrD + shortlink: https://sg.run/DAlP + source: https://semgrep.dev/r/javascript.aws-lambda.security.sequelize-sqli.sequelize-sqli + subcategory: + - vuln + technology: + - aws-lambda + - sequelize + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $DB.query($QUERY, ...) + - pattern-either: + - pattern-inside: "require('sequelize')\n...\n" + - pattern-inside: "import 'sequelize'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.tainted-html-response.tainted-html-response + languages: + - javascript + - typescript + message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of + rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could + let attackers steal sensitive user data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18254 + rule_id: OrUJBY + rv_id: 1263111 + url: + https://semgrep.dev/playground/r/BjTkZ8D/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + version_id: BjTkZ8D + shortlink: https://sg.run/0Gvj + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-response.tainted-html-response + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $BODY + - pattern-inside: "{..., headers: {..., 'Content-Type': 'text/html', ...}, body: $BODY, ... }\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - javascript + - typescript + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18483 + rule_id: PeUxwW + rv_id: 1263112 + url: + https://semgrep.dev/playground/r/DkTRbvp/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + version_id: DkTRbvp + shortlink: https://sg.run/Lgqr + source: https://semgrep.dev/r/javascript.aws-lambda.security.tainted-html-string.tainted-html-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$HTMLSTR\" + $EXPR\n" + - pattern: "\"$HTMLSTR\".concat(...)\n" + - pattern: $UTIL.format($HTMLSTR, ...) + - pattern: format($HTMLSTR, ...) + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - patterns: + - pattern: "`...${...}...`\n" + - pattern-regex: ".*<\\w+.*\n" + - pattern-not-inside: "console.$LOG(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern: $EVENT + severity: WARNING +- id: javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + languages: + - javascript + - typescript + message: The `vm` module enables compiling and running code within V8 Virtual Machine contexts. The `vm` module is not + a security mechanism. Do not use it to run untrusted code. If code passed to `vm` functions is controlled by user + input it could result in command injection. Do not let user input in `vm` functions. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18256 + rule_id: v8UOdZ + rv_id: 1263114 + url: + https://semgrep.dev/playground/r/0bTKz9J/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + version_id: 0bTKz9J + shortlink: https://sg.run/q9w7 + source: https://semgrep.dev/r/javascript.aws-lambda.security.vm-runincontext-injection.vm-runincontext-injection + subcategory: + - vuln + technology: + - javascript + - aws-lambda + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('vm');\n...\n" + - pattern-inside: "import 'vm'\n...\n" + - pattern-either: + - pattern: $VM.runInContext($X,...) + - pattern: $VM.runInNewContext($X,...) + - pattern: $VM.runInThisContext($X,...) + - pattern: $VM.compileFunction($X,...) + - pattern: new $VM.Script($X,...) + - pattern: new $VM.SourceTextModule($X,...) + - pattern: runInContext($X,...) + - pattern: runInNewContext($X,...) + - pattern: runInThisContext($X,...) + - pattern: compileFunction($X,...) + - pattern: new Script($X,...) + - pattern: new SourceTextModule($X,...) + pattern-sources: + - patterns: + - pattern: $EVENT + - pattern-either: + - pattern-inside: "exports.handler = function ($EVENT, ...) {\n ...\n}\n" + - pattern-inside: "function $FUNC ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + - pattern-inside: "$FUNC = function ($EVENT, ...) {...}\n...\nexports.handler = $FUNC\n" + severity: ERROR +- id: javascript.browser.security.open-redirect.js-open-redirect + languages: + - javascript + - typescript + message: The application accepts potentially user-controlled input `$PROP` which can control the location of the + current window context. This can lead two types of vulnerabilities open-redirection and Cross-Site-Scripting (XSS) + with JavaScript URIs. It is recommended to validate user-controllable input before allowing it to control the + redirection. + metadata: + asvs: + control_id: 5.5.1 Insecue Redirect + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9243 + rule_id: WAUopl + rv_id: 1263122 + url: https://semgrep.dev/playground/r/pZT03x0/javascript.browser.security.open-redirect.js-open-redirect + version_id: pZT03x0 + shortlink: https://sg.run/3xRe + source: https://semgrep.dev/r/javascript.browser.security.open-redirect.js-open-redirect + subcategory: + - vuln + technology: + - browser + vulnerability_class: + - Open Redirect + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: location.href = $SINK + - pattern: $THIS. ... .location.href = $SINK + - pattern: location.replace($SINK) + - pattern: $THIS. ... .location.replace($SINK) + - pattern: location = $SINK + - pattern: $WINDOW. ... .location = $SINK + - focus-metavariable: $SINK + - metavariable-pattern: + metavariable: $SINK + patterns: + - pattern-not: "\"...\" + $VALUE\n" + - pattern-not: "`...${$VALUE}`\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "new URLSearchParams($WINDOW. ... .location.search).get('...')\n" + - pattern: "new URLSearchParams(location.search).get('...')\n" + - pattern: "new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')\n" + - pattern: "new URLSearchParams(location.hash.substring(1)).get('...')\n" + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.search)\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.search)\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.hash.substring(1))\n...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.hash.substring(1))\n...\n" + - pattern: $PROPS.get('...') + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URL($WINDOW. ... .location.href)\n...\n" + - pattern-inside: "$PROPS = new URL(location.href)\n...\n" + - pattern: $PROPS.searchParams.get('...') + - patterns: + - pattern-either: + - pattern: "new URL($WINDOW. ... .location.href).searchParams.get('...')\n" + - pattern: "new URL(location.href).searchParams.get('...')\n" + severity: WARNING +- id: javascript.browser.security.raw-html-concat.raw-html-concat + languages: + - javascript + - typescript + message: User controlled data in a HTML string may result in XSS + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/xss/ + semgrep.dev: + rule: + origin: community + r_id: 9244 + rule_id: 0oU5b5 + rv_id: 1263123 + url: https://semgrep.dev/playground/r/2KTv2wp/javascript.browser.security.raw-html-concat.raw-html-concat + version_id: 2KTv2wp + shortlink: https://sg.run/4xAx + source: https://semgrep.dev/r/javascript.browser.security.raw-html-concat.raw-html-concat + subcategory: + - vuln + technology: + - browser + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $STRING + $EXPR + - pattern-not: $STRING + "..." + - metavariable-pattern: + language: generic + metavariable: $STRING + patterns: + - pattern: <$TAG ... + - pattern-not: <$TAG ...>...... + - patterns: + - pattern: $EXPR + $STRING + - pattern-not: '"..." + $STRING' + - metavariable-pattern: + language: generic + metavariable: $STRING + patterns: + - pattern: '... ,...) + - pattern-not-inside: "$OPTS = <... {name:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.name = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + languages: + - javascript + - typescript + message: 'Default session middleware settings: `domain` not set. It indicates the domain of the cookie; use it to compare + against the domain of the server in which the URL is being requested. If they match, then check the path attribute next.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9269 + rule_id: ZqU5Pn + rv_id: 1263133 + url: + https://semgrep.dev/playground/r/w8TRoyd/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + version_id: w8TRoyd + shortlink: https://sg.run/rd41 + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-domain + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{domain:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{domain:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {domain:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {domain:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.domain = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.domain = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + languages: + - javascript + - typescript + message: 'Default session middleware settings: `expires` not set. Use it to set expiration date for persistent cookies.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9271 + rule_id: EwU2DZ + rv_id: 1263135 + url: + https://semgrep.dev/playground/r/O9TpxRq/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + version_id: O9TpxRq + shortlink: https://sg.run/N4eG + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-expires + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{expires:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{expires:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {expires:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {expires:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.expires = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.expires = ...;\n...\n$SESSION($OPTS,...);" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + languages: + - javascript + - typescript + message: 'Default session middleware settings: `httpOnly` not set. It ensures the cookie is sent only over HTTP(S), not + client JavaScript, helping to protect against cross-site scripting attacks.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9268 + rule_id: d8UjGo + rv_id: 1263132 + url: + https://semgrep.dev/playground/r/kbTzGev/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + version_id: kbTzGev + shortlink: https://sg.run/ydBO + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-httponly + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{httpOnly:true}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{httpOnly:true}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {httpOnly:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {httpOnly:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.httpOnly = true;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.httpOnly = true;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + languages: + - javascript + - typescript + message: 'Default session middleware settings: `path` not set. It indicates the path of the cookie; use it to compare against + the request path. If this and domain match, then send the cookie in the request.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9270 + rule_id: nJUz4X + rv_id: 1263134 + url: + https://semgrep.dev/playground/r/xyTjzQD/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + version_id: xyTjzQD + shortlink: https://sg.run/b7pd + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-path + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{path:...}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{path:...}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {path:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {path:...} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.path = ...;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.path = ...;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + languages: + - javascript + - typescript + message: 'Default session middleware settings: `secure` not set. It ensures the browser only sends the cookie over HTTPS.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9267 + rule_id: v8Unzw + rv_id: 1263131 + url: + https://semgrep.dev/playground/r/NdTzyrv/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + version_id: NdTzyrv + shortlink: https://sg.run/9oKz + source: + https://semgrep.dev/r/javascript.express.security.audit.express-cookie-settings.express-cookie-session-no-secure + source-rule-url: https://expressjs.com/en/advanced/best-practice-security.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('cookie-session');\n...\n" + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern: $SESSION(...) + - pattern-not-inside: $SESSION(<... {cookie:{secure:true}} ...>,...) + - pattern-not-inside: "$OPTS = <... {cookie:{secure:true}} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE = <... {secure:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie = <... {secure:true} ...>;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$COOKIE.secure = true;\n...\n$SESSION($OPTS,...);\n" + - pattern-not-inside: "$OPTS = ...;\n...\n$OPTS.cookie.secure = true;\n...\n$SESSION($OPTS,...);\n" + severity: WARNING +- id: javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + languages: + - javascript + - typescript + message: No token revoking configured for `express-jwt`. A leaked token could still be used and unable to be revoked. + Consider using function as the `isRevoked` option. + metadata: + asvs: + control_id: 3.5.3 Insecure Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 9272 + rule_id: 7KUQ9k + rv_id: 1263137 + url: + https://semgrep.dev/playground/r/vdT06Bg/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + version_id: vdT06Bg + shortlink: https://sg.run/kXNo + source: https://semgrep.dev/r/javascript.express.security.audit.express-jwt-not-revoked.express-jwt-not-revoked + source-rule-url: https://github.com/goldbergyoni/nodebestpractices/blob/master/sections/security/expirejwt.md + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "$JWT = require('express-jwt');\n...\n" + - pattern: $JWT(...) + - pattern-not-inside: $JWT(<... {isRevoked:...} ...>,...) + - pattern-not-inside: "$OPTS = <... {isRevoked:...} ...>;\n...\n$JWT($OPTS,...);" + severity: WARNING +- id: javascript.express.security.audit.express-libxml-noent.express-libxml-noent + languages: + - javascript + - typescript + message: The libxml library processes user-input with the `noent` attribute is set to `true` which can lead to being + vulnerable to XML External Entities (XXE) type attacks. It is recommended to set `noent` to `false` when using this + feature to ensure you are protected. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22079 + rule_id: pKUNeD + rv_id: 1263138 + url: + https://semgrep.dev/playground/r/d6TyxpX/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + version_id: d6TyxpX + shortlink: https://sg.run/Z75x + source: https://semgrep.dev/r/javascript.express.security.audit.express-libxml-noent.express-libxml-noent + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + options: + interfile: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$XML = require('$IMPORT')\n...\n" + - pattern-inside: "import $XML from '$IMPORT'\n ...\n" + - pattern-inside: "import * as $XML from '$IMPORT'\n...\n" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(libxmljs|libxmljs2)$ + - pattern-inside: $XML.$FUNC($QUERY, {...,noent:true,...}) + - metavariable-regex: + metavariable: $FUNC + regex: ^(parseXmlString|parseXml)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: javascript.express.security.audit.express-open-redirect.express-open-redirect + languages: + - javascript + - typescript + message: The application redirects to a URL specified by user-supplied input `$REQ` that is not validated. This could + redirect users to malicious locations. Consider using an allow-list approach to validate URLs, or warn users they + are being redirected to a third-party website. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22081 + rule_id: X5ULkq + rv_id: 1263140 + url: + https://semgrep.dev/playground/r/nWT2L0v/javascript.express.security.audit.express-open-redirect.express-open-redirect + version_id: nWT2L0v + shortlink: https://sg.run/EpoP + source: https://semgrep.dev/r/javascript.express.security.audit.express-open-redirect.express-open-redirect + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Open Redirect + mode: taint + options: + symbolic_propagation: true + taint_unify_mvars: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE) + - pattern: $RES.redirect("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...]) + - pattern: $RES.redirect("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $RES.redirect(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $HTTP + regex: ^https?:\/\/$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ. ... .$VALUE) + - pattern: $RES.redirect($REQ. ... .$VALUE + $...A) + - pattern: $RES.redirect(`${$REQ. ... .$VALUE}...`) + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern: $RES.redirect($REQ.$VALUE['...']) + - pattern: $RES.redirect($REQ.$VALUE['...'] + $...A) + - pattern: $RES.redirect(`${$REQ.$VALUE['...']}...`) + - pattern: $REQ.$VALUE + - patterns: + - pattern-either: + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...']\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = $REQ.$VALUE['...'] + $...A\n... \n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE}...`\n...\n" + - pattern-inside: "$ASSIGN = `${$REQ.$VALUE['...']}...`\n... \n" + - pattern-either: + - pattern: $RES.redirect($ASSIGN) + - pattern: $RES.redirect($ASSIGN + $...FOO) + - pattern: $RES.redirect(`${$ASSIGN}...`) + - focus-metavariable: $ASSIGN + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + languages: + - javascript + - typescript + message: Possible writing outside of the destination, make sure that the target path is nested in the intended + destination + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9273 + rule_id: L1Uyb8 + rv_id: 1263141 + url: + https://semgrep.dev/playground/r/ExTExX0/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + version_id: ExTExX0 + shortlink: https://sg.run/weRn + source: + https://semgrep.dev/r/javascript.express.security.audit.express-path-join-resolve-traversal.express-path-join-resolve-traversal + subcategory: + - vuln + technology: + - express + - node.js + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - pattern: $Y.replace(...) + - pattern: $Y.indexOf(...) + - pattern: "function ... (...) {\n ...\n <... $Y.indexOf(...) ...>\n ...\n}\n" + - patterns: + - pattern: $FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: sanitize + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern-inside: "$PATH = require('path');\n...\n" + - pattern-inside: "import $PATH from 'path';\n...\n" + - pattern-either: + - pattern: $PATH.join(...,$SINK,...) + - pattern: $PATH.resolve(...,$SINK,...) + - patterns: + - focus-metavariable: $SINK + - pattern-inside: "import 'path';\n...\n" + - pattern-either: + - pattern: path.join(...,$SINK,...) + - pattern: path.resolve(...,$SINK,...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.express-res-sendfile.express-res-sendfile + languages: + - javascript + - typescript + message: The application processes user-input, this is passed to res.sendFile which can allow an attacker to + arbitrarily read files on the system through path traversal. It is recommended to perform input validation in + addition to canonicalizing the path. This allows you to validate the path against the intended directory it should + be accessing. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-73: External Control of File Name or Path' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22082 + rule_id: j2UzDx + rv_id: 1263142 + url: + https://semgrep.dev/playground/r/7ZTE3X9/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + version_id: 7ZTE3X9 + shortlink: https://sg.run/7DJk + source: https://semgrep.dev/r/javascript.express.security.audit.express-res-sendfile.express-res-sendfile + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.$METH($QUERY,...) + - pattern-not-inside: $RES.$METH($QUERY,$OPTIONS) + - metavariable-regex: + metavariable: $METH + regex: ^(sendfile|sendFile)$ + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "function ... (...,$REQ: $TYPE, ...) {...}\n" + - metavariable-regex: + metavariable: $TYPE + regex: ^(string|String) + severity: WARNING +- id: javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22083 + rule_id: 10Uo39 + rv_id: 1263143 + url: + https://semgrep.dev/playground/r/LjTkgle/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + version_id: LjTkgle + shortlink: https://sg.run/LYvG + source: + https://semgrep.dev/r/javascript.express.security.audit.express-session-hardcoded-secret.express-session-hardcoded-secret + subcategory: + - vuln + technology: + - express + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + patterns: + - pattern-either: + - pattern-inside: "$SESSION = require('express-session');\n...\n" + - pattern-inside: "import $SESSION from 'express-session'\n...\n" + - pattern-inside: "import {..., $SESSION, ...} from 'express-session'\n...\n" + - pattern-inside: "import * as $SESSION from 'express-session'\n...\n" + - patterns: + - pattern-either: + - pattern-inside: $APP.use($SESSION({...})) + - pattern: "$SECRET = $VALUE\n...\n$APP.use($SESSION($SECRET))\n" + - pattern: "secret: '$Y'\n" + severity: WARNING +- id: javascript.express.security.audit.express-ssrf.express-ssrf + languages: + - javascript + - typescript + message: 'The following request $REQUEST.$METHOD() was found to be crafted from user-input `$REQ` which can lead to Server-Side + Request Forgery (SSRF) vulnerabilities. It is recommended where possible to not allow user-input to craft the base request, + but to be treated as part of the path or query parameter. When user-input is necessary to craft the request, it is recommeneded + to follow OWASP best practices to prevent abuse. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22554 + rule_id: eqU9l2 + rv_id: 1263144 + url: https://semgrep.dev/playground/r/8KT5rBr/javascript.express.security.audit.express-ssrf.express-ssrf + version_id: 8KT5rBr + shortlink: https://sg.run/0PNw + source: https://semgrep.dev/r/javascript.express.security.audit.express-ssrf.express-ssrf + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + options: + taint_unify_mvars: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ. ... .$VALUE + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ. ... .$VALUE}...`) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...]) + - pattern: $REQUEST.$METHOD("$HTTP"+$REQ.$VALUE[...] + $...A) + - pattern: $REQUEST.$METHOD(`$HTTP${$REQ.$VALUE[...]}...`) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQ. ... .$VALUE + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE,...) + - pattern: $REQUEST.$METHOD($REQ. ... .$VALUE + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ. ... .$VALUE}...`,...) + - pattern: $REQ. ... .$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'],...) + - pattern: $REQUEST.$METHOD($REQ.$VALUE['...'] + $...A,...) + - pattern: $REQUEST.$METHOD(`${$REQ.$VALUE['...']}...`,...) + - pattern: $REQ.$VALUE + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + - patterns: + - pattern-either: + - pattern-inside: "$REQUEST = require('request')\n...\n" + - pattern-inside: "import * as $REQUEST from 'request'\n...\n" + - pattern-inside: "import $REQUEST from 'request'\n...\n" + - pattern-either: + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...']\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = $REQ. ... .$VALUE['...'] + $...A\n... \n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE}...`\n...\n" + - pattern-inside: "$ASSIGN = `${$REQ. ... .$VALUE['...']}...`\n... \n" + - patterns: + - pattern-either: + - pattern-inside: "$ASSIGN = \"$HTTP\"+ $REQ. ... .$VALUE\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ. ... .$VALUE + $...A\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ.$VALUE[...]\n...\n" + - pattern-inside: "$ASSIGN = \"$HTTP\"+$REQ.$VALUE[...] + $...A\n...\n" + - pattern-inside: "$ASSIGN = `$HTTP${$REQ.$VALUE[...]}...`\n...\n" + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern-either: + - pattern: $REQUEST.$METHOD($ASSIGN,...) + - pattern: $REQUEST.$METHOD($ASSIGN + $...FOO,...) + - pattern: $REQUEST.$METHOD(`${$ASSIGN}...`,...) + - patterns: + - pattern-either: + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN,...) + - pattern: $REQUEST.$METHOD("$HTTP"+$ASSIGN + $...A,...) + - pattern: $REQUEST.$METHOD(`$HTTP${$ASSIGN}...`,...) + - metavariable-regex: + metavariable: $HTTP + regex: ^(https?:\/\/|//)$ + - pattern: $ASSIGN + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|patch|del|head|delete)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, ...) {...} + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,...) =>\n{...}\n" + - pattern-inside: "({ $REQ }: $EXPRESS.Request,...) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: + javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + languages: + - javascript + - typescript + message: The following function call $SER.$FUNC accepts user controlled data which can result in Remote Code Execution + (RCE) through Object Deserialization. It is recommended to use secure data processing alternatives such as + JSON.parse() and Buffer.from(). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Deserialization_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 22084 + rule_id: 9AUyqj + rv_id: 1263145 + url: + https://semgrep.dev/playground/r/gETB7nD/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + version_id: gETB7nD + shortlink: https://sg.run/8W5j + source: + https://semgrep.dev/r/javascript.express.security.audit.express-third-party-object-deserialization.express-third-party-object-deserialization + source_rule_url: + - https://github.com/ajinabraham/njsscan/blob/75bfbeb9c8d72999e4d527dfa2548f7f0f3cc48a/njsscan/rules/semantic_grep/eval/eval_deserialize.yaml + subcategory: + - vuln + technology: + - express + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + options: + interfile: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$SER = require('$IMPORT')\n...\n" + - pattern-inside: "import $SER from '$IMPORT'\n ...\n" + - pattern-inside: "import * as $SER from '$IMPORT'\n...\n" + - metavariable-regex: + metavariable: $IMPORT + regex: ^(node-serialize|serialize-to-js)$ + - pattern: $SER.$FUNC(...) + - metavariable-regex: + metavariable: $FUNC + regex: ^(unserialize|deserialize)$ + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: WARNING +- id: javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + languages: + - javascript + - typescript + message: Xml Parser is used inside Request Event. Make sure that unverified user data can not reach the XML Parser, as + it can result in XML External or Internal Entity (XXE) Processing vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.npmjs.com/package/xml2json + semgrep.dev: + rule: + origin: community + r_id: 9274 + rule_id: 8GUjkk + rv_id: 1263146 + url: + https://semgrep.dev/playground/r/QkTGqgo/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + version_id: QkTGqgo + shortlink: https://sg.run/x1AA + source: + https://semgrep.dev/r/javascript.express.security.audit.express-xml2json-xxe-event.express-xml2json-xxe-event + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('xml2json');\n...\n" + - pattern-inside: "import 'xml2json';\n...\n" + - pattern: $REQ.on('...', function(...) { ... $EXPAT.toJson($INPUT,...); ... }) + - focus-metavariable: $INPUT + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) => {...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.res-render-injection.res-render-injection + languages: + - javascript + - typescript + message: User controllable data `$REQ` enters `$RES.render(...)` this can lead to the loading of other HTML/templating + pages that they may not be authorized to render. An attacker may attempt to use directory traversal techniques e.g. + `../folder/index` to access other HTML pages on the file system. Where possible, do not allow users to define what + should be loaded in $RES.render or use an allow list for the existing application. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - http://expressjs.com/en/4x/api.html#res.render + semgrep.dev: + rule: + origin: community + r_id: 9276 + rule_id: QrUzrq + rv_id: 1263149 + url: + https://semgrep.dev/playground/r/PkTR3OY/javascript.express.security.audit.res-render-injection.res-render-injection + version_id: PkTR3OY + shortlink: https://sg.run/eLjd + source: https://semgrep.dev/r/javascript.express.security.audit.res-render-injection.res-render-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authorization + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.render($SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.audit.xss.direct-response-write.direct-response-write + languages: + - javascript + - typescript + message: Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and + may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render + safely escaped HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9277 + rule_id: 3qUPA1 + rv_id: 1263150 + url: + https://semgrep.dev/playground/r/JdTzxeg/javascript.express.security.audit.xss.direct-response-write.direct-response-write + version_id: JdTzxeg + shortlink: https://sg.run/vzGl + source: https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + options: + interfile: true + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'express-xss-sanitizer';\n...\n" + - pattern-inside: "import * as $S from \"express-xss-sanitizer\";\n...\n" + - pattern-inside: "const { ..., $S, ... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "var { ..., $S, ... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "let { ...,$S,... } = require('express-xss-sanitizer');\n...\n" + - pattern-inside: "$S = require(\"express-xss-sanitizer\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern: $RES. ... .type('$F'). ... .send(...) + - metavariable-regex: + metavariable: $F + regex: (?!.*text/html) + - patterns: + - pattern-inside: "$X = [...];\n...\n" + - pattern: "if(<... !$X.includes($SOURCE)...>) {\n ...\n return ...\n}\n...\n" + - pattern: $SOURCE + pattern-sinks: + - patterns: + - pattern-inside: function ... (..., $RES,...) {...} + - pattern-either: + - pattern: $RES.write($ARG) + - pattern: $RES.send($ARG) + - pattern-not: $RES. ... .set('...'). ... .send($ARG) + - pattern-not: $RES. ... .type('...'). ... .send($ARG) + - pattern-not-inside: $RES.$METHOD({ ... }) + - focus-metavariable: $ARG + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-not-inside: "function ... ($REQ, $RES) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "$APP.$METHOD(..., function $FUNC($REQ, $RES) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n\ + })\n" + - pattern-not-inside: "function ... ($REQ, $RES, $NEXT) {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "function ... ($REQ, $RES) {\n ...\n $RES.set('$TYPE')\n}\n" + - pattern-not-inside: "$APP.$METHOD(..., function $FUNC($REQ, $RES) {\n ...\n $RES.set('$TYPE')\n})\n" + - pattern-not-inside: "function ... ($REQ, $RES, $NEXT) {\n ...\n $RES.set('$TYPE')\n}\n" + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{\n ...\n $RES.$SET('Content-Type', + '$TYPE')\n}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response) => {\n ...\n $RES.$SET('Content-Type', '$TYPE')\n}\n" + - pattern-not-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{\n ...\n $RES.set('$TYPE')\n\ + }\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: body + severity: WARNING +- id: javascript.express.security.cors-misconfiguration.cors-misconfiguration + languages: + - javascript + - typescript + message: By letting user input control CORS parameters, there is a risk that software does not properly verify that + the source of data or communication is valid. Use literal values for CORS settings. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-346: Origin Validation Error' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS + semgrep.dev: + rule: + origin: community + r_id: 13580 + rule_id: 5rULJQ + rv_id: 1263162 + url: + https://semgrep.dev/playground/r/YDTZe8Y/javascript.express.security.cors-misconfiguration.cors-misconfiguration + version_id: YDTZe8Y + shortlink: https://sg.run/nKXO + source: https://semgrep.dev/r/javascript.express.security.cors-misconfiguration.cors-misconfiguration + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authentication + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, $X) + - pattern: $RES.header($HEADER, $X) + - pattern: $RES.setHeader($HEADER, $X) + - pattern: "$RES.set({$HEADER: $X}, ...)\n" + - pattern: "$RES.writeHead($STATUS, {$HEADER: $X}, ...)\n" + - focus-metavariable: $X + - metavariable-regex: + metavariable: $HEADER + regex: .*(Access-Control-Allow-Origin|access-control-allow-origin).* + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-expat-xxe.express-expat-xxe + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or + Internal Entity (XXE) Processing vulnerabilities. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://github.com/astro/node-expat + semgrep.dev: + rule: + origin: community + r_id: 9251 + rule_id: zdUkJl + rv_id: 1263164 + url: https://semgrep.dev/playground/r/o5TbD5l/javascript.express.security.express-expat-xxe.express-expat-xxe + version_id: o5TbD5l + shortlink: https://sg.run/BkXx + source: https://semgrep.dev/r/javascript.express.security.express-expat-xxe.express-expat-xxe + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$XML = require('node-expat')\n...\n" + - pattern-inside: "import $XML from 'node-expat'\n...\n" + - pattern-inside: "import * as $XML from 'node-expat'\n...\n" + - pattern-either: + - pattern-inside: "$PARSER = new $XML.Parser(...);\n...\n" + - pattern-either: + - pattern: $PARSER.parse($QUERY) + - pattern: $PARSER.write($QUERY) + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + languages: + - javascript + - typescript + message: User data from `$REQ` is being compiled into the template, which can lead to a Server Side Template Injection + (SSTI) vulnerability. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 19226 + rule_id: EwUr9k + rv_id: 1263165 + url: + https://semgrep.dev/playground/r/zyTb2eD/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + version_id: zyTb2eD + shortlink: https://sg.run/b49v + source: + https://semgrep.dev/r/javascript.express.security.express-insecure-template-usage.express-insecure-template-usage + source_rule_url: + - https://github.com/github/codeql/blob/2ba2642c7ab29b9eedef33bcc2b8cd1d203d0c10/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/template-sinks.js + subcategory: + - vuln + technology: + - javascript + - typescript + - express + - pug + - jade + - dot + - ejs + - nunjucks + - lodash + - handlbars + - mustache + - hogan.js + - eta + - squirrelly + vulnerability_class: + - Code Injection + mode: taint + options: + interfile: true + pattern-propagators: + - from: $E + pattern: $MODEL.$FIND($E).then((...,$S,...)=>{...}) + to: $S + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('pug')\n...\n" + - pattern-inside: "import * as $PUG from 'pug'\n...\n" + - pattern-inside: "$PUG = require('jade')\n...\n" + - pattern-inside: "import * as $PUG from 'jade'\n...\n" + - pattern-either: + - pattern: $PUG.compile(...) + - pattern: $PUG.compileClient(...) + - pattern: $PUG.compileClientWithDependenciesTracked(...) + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('dot')\n...\n" + - pattern-inside: "import * as $PUG from 'dot'\n...\n" + - pattern-either: + - pattern: $PUG.template(...) + - pattern: $PUG.compile(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('ejs')\n...\n" + - pattern-inside: "import * as $PUG from 'ejs'\n...\n" + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('nunjucks')\n...\n" + - pattern-inside: "import * as $PUG from 'nunjucks'\n...\n" + - pattern-either: + - pattern: $PUG.renderString(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('lodash')\n...\n" + - pattern-inside: "import * as $PUG from 'lodash'\n...\n" + - pattern-either: + - pattern: $PUG.template(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('mustache')\n...\n" + - pattern-inside: "import * as $PUG from 'mustache'\n...\n" + - pattern-inside: "$PUG = require('eta')\n...\n" + - pattern-inside: "import * as $PUG from 'eta'\n...\n" + - pattern-inside: "$PUG = require('squirrelly')\n...\n" + - pattern-inside: "import * as $PUG from 'squirrelly'\n...\n" + - pattern-either: + - pattern: $PUG.render(...) + - patterns: + - pattern-either: + - pattern-inside: "$PUG = require('hogan.js')\n...\n" + - pattern-inside: "import * as $PUG from 'hogan.js'\n...\n" + - pattern-inside: "$PUG = require('handlebars')\n...\n" + - pattern-inside: "import * as $PUG from 'handlebars'\n...\n" + - pattern-either: + - pattern: $PUG.compile(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9252 + rule_id: pKUOjy + rv_id: 1263166 + url: + https://semgrep.dev/playground/r/pZT03Q0/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + version_id: pZT03Q0 + shortlink: https://sg.run/Do1d + source: https://semgrep.dev/r/javascript.express.security.express-jwt-hardcoded-secret.express-jwt-hardcoded-secret + subcategory: + - audit + technology: + - express + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + patterns: + - pattern-either: + - pattern-inside: "$JWT = require('express-jwt');\n...\n" + - pattern-inside: "import $JWT from 'express-jwt';\n...\n" + - pattern-inside: "import * as $JWT from 'express-jwt';\n...\n" + - pattern-inside: "import { ..., $JWT, ... } from 'express-jwt';\n...\n" + - pattern-either: + - pattern: "$JWT({...,secret: \"$Y\",...},...)\n" + - pattern: "$OPTS = \"$Y\";\n...\n$JWT({...,secret: $OPTS},...);\n" + - focus-metavariable: $Y + severity: WARNING +- id: javascript.express.security.express-phantom-injection.express-phantom-injection + languages: + - javascript + - typescript + message: If unverified user data can reach the `phantom` methods it can result in Server-Side Request Forgery + vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://phantomjs.org/page-automation.html + semgrep.dev: + rule: + origin: community + r_id: 9253 + rule_id: 2ZUbx3 + rv_id: 1263167 + url: + https://semgrep.dev/playground/r/2KTv26p/javascript.express.security.express-phantom-injection.express-phantom-injection + version_id: 2KTv26p + shortlink: https://sg.run/W8BL + source: https://semgrep.dev/r/javascript.express.security.express-phantom-injection.express-phantom-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('phantom');\n...\n" + - pattern-inside: "import 'phantom';\n...\n" + - pattern-either: + - pattern: $PAGE.open($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.openUrl($SINK,...) + - pattern: $PAGE.evaluateJavaScript($SINK,...) + - pattern: $PAGE.property("content",$SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + languages: + - javascript + - typescript + message: If unverified user data can reach the `puppeteer` methods it can result in Server-Side Request Forgery + vulnerabilities + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://pptr.dev/api/puppeteer.page + semgrep.dev: + rule: + origin: community + r_id: 9254 + rule_id: X5U8Nz + rv_id: 1263168 + url: + https://semgrep.dev/playground/r/X0TzyJY/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + version_id: X0TzyJY + shortlink: https://sg.run/0QJB + source: https://semgrep.dev/r/javascript.express.security.express-puppeteer-injection.express-puppeteer-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('puppeteer');\n...\n" + - pattern-inside: "import 'puppeteer';\n...\n" + - pattern-either: + - pattern: $PAGE.goto($SINK,...) + - pattern: $PAGE.setContent($SINK,...) + - pattern: $PAGE.evaluate($SINK,...) + - pattern: $PAGE.evaluate($CODE,$SINK,...) + - pattern: $PAGE.evaluateHandle($SINK,...) + - pattern: $PAGE.evaluateHandle($CODE,$SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($SINK,...) + - pattern: $PAGE.evaluateOnNewDocument($CODE,$SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `sandbox`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9255 + rule_id: j2UvXB + rv_id: 1263169 + url: + https://semgrep.dev/playground/r/jQTn59D/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + version_id: jQTn59D + shortlink: https://sg.run/KlwL + source: https://semgrep.dev/r/javascript.express.security.express-sandbox-injection.express-sandbox-code-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$SANDBOX = require('sandbox');\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$S = new $SANDBOX(...);\n...\n" + - pattern: "$S.run(...)\n" + - pattern: "new $SANDBOX($OPTS).run(...)\n" + - pattern: new $SANDBOX().run(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-vm-injection.express-vm-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `$VM`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 12821 + rule_id: DbUKPX + rv_id: 1263170 + url: + https://semgrep.dev/playground/r/1QTypXQ/javascript.express.security.express-vm-injection.express-vm-injection + version_id: 1QTypXQ + shortlink: https://sg.run/jkqJ + source: https://semgrep.dev/r/javascript.express.security.express-vm-injection.express-vm-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$VM = require('vm');\n...\n" + - pattern-either: + - pattern: "$VM.runInContext(...)\n" + - pattern: "$VM.runInNewContext(...)\n" + - pattern: "$VM.compileFunction(...)\n" + - pattern: "$VM.runInThisContext(...)\n" + - pattern: new $VM.Script(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.express-vm2-injection.express-vm2-injection + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach `vm2`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 12822 + rule_id: WAUPXJ + rv_id: 1263171 + url: + https://semgrep.dev/playground/r/9lT4bnX/javascript.express.security.express-vm2-injection.express-vm2-injection + version_id: 9lT4bnX + shortlink: https://sg.run/1GWv + source: https://semgrep.dev/r/javascript.express.security.express-vm2-injection.express-vm2-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "require('vm2')\n...\n" + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "$VM = new VM(...)\n...\n" + - pattern-inside: "$VM = new NodeVM(...)\n...\n" + - pattern: "$VM.run(...)\n" + - pattern: "new VM(...).run(...)\n" + - pattern: "new NodeVM(...).run(...)\n" + - pattern: "new VMScript(...)\n" + - pattern: "new VM(...)\n" + - pattern: new NodeVM(...) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + languages: + - javascript + - typescript + message: Make sure that unverified user data can not reach the XML Parser, as it can result in XML External or + Internal Entity (XXE) Processing vulnerabilities + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.npmjs.com/package/xml2json + semgrep.dev: + rule: + origin: community + r_id: 9264 + rule_id: x8Uneb + rv_id: 1263174 + url: + https://semgrep.dev/playground/r/bZT534J/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + version_id: bZT534J + shortlink: https://sg.run/XBD4 + source: https://semgrep.dev/r/javascript.express.security.express-xml2json-xxe.express-xml2json-xxe + subcategory: + - vuln + technology: + - express + vulnerability_class: + - XML Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "require('xml2json');\n...\n" + - pattern-inside: "import 'xml2json';\n...\n" + - pattern: $EXPAT.toJson($SINK,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: javascript.express.security.injection.raw-html-format.raw-html-format + languages: + - javascript + - typescript + message: User data flows into the host portion of this manually-constructed HTML. This can introduce a + Cross-Site-Scripting (XSS) vulnerability if this comes from user-provided input. Consider using a sanitization + library such as DOMPurify to sanitize the HTML within. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 14691 + rule_id: 5rUL0X + rv_id: 1263175 + url: + https://semgrep.dev/playground/r/NdTzyQv/javascript.express.security.injection.raw-html-format.raw-html-format + version_id: NdTzyQv + shortlink: https://sg.run/5DO3 + source: https://semgrep.dev/r/javascript.express.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" + $EXPR' + - pattern: '"$HTMLSTR".concat(...)' + - pattern: util.format($HTMLSTR, ...) + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - patterns: + - pattern: "`...`\n" + - pattern-regex: ".*<\\w+.*\n" + requires: (EXPRESS and not CLEAN) or (EXPRESSTS and not CLEAN) + pattern-sources: + - label: EXPRESS + patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - label: EXPRESSTS + patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - by-side-effect: true + label: CLEAN + patterns: + - pattern-either: + - pattern: $A($SOURCE) + - pattern: $SANITIZE. ... .$A($SOURCE) + - pattern: $A. ... .$SANITIZE($SOURCE) + - focus-metavariable: $SOURCE + - metavariable-regex: + metavariable: $A + regex: (?i)(.*valid|.*sanitiz) + severity: WARNING +- id: javascript.express.security.require-request.require-request + languages: + - javascript + - typescript + message: If an attacker controls the x in require(x) then they can cause code to load that was not intended to run on + the server. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-706: Use of Incorrectly-Resolved Name or Reference' + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/google/node-sec-roadmap/blob/master/chapter-2/dynamism.md#dynamism-when-you-need-it + semgrep.dev: + rule: + origin: community + r_id: 9265 + rule_id: OrU3WK + rv_id: 1263177 + url: https://semgrep.dev/playground/r/w8TRo0d/javascript.express.security.require-request.require-request + version_id: w8TRo0d + shortlink: https://sg.run/jRbl + source: https://semgrep.dev/r/javascript.express.security.require-request.require-request + source-rule-url: https://nodesecroadmap.fyi/chapter-1/threat-UIR.html + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Improper Authorization + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: require($SINK) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: ERROR +- id: javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + languages: + - javascript + - typescript + message: By letting user input control `X-Frame-Options` header, there is a risk that software does not properly + verify whether or not a browser should be allowed to render a page in an `iframe`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-451: User Interface (UI) Misrepresentation of Critical Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + semgrep.dev: + rule: + origin: community + r_id: 13581 + rule_id: GdUrLy + rv_id: 1263178 + url: + https://semgrep.dev/playground/r/xyTjz3D/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + version_id: xyTjz3D + shortlink: https://sg.run/EvjA + source: + https://semgrep.dev/r/javascript.express.security.x-frame-options-misconfiguration.x-frame-options-misconfiguration + subcategory: + - vuln + technology: + - express + vulnerability_class: + - Other + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $RES.set($HEADER, ...) + - pattern: $RES.header($HEADER, ...) + - pattern: $RES.setHeader($HEADER, ...) + - pattern: "$RES.set({$HEADER: ...}, ...)\n" + - pattern: "$RES.writeHead($STATUS, {$HEADER: ...}, ...)\n" + - metavariable-regex: + metavariable: $HEADER + regex: .*(X-Frame-Options|x-frame-options).* + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + severity: WARNING +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9293 + rule_id: JDUyRl + rv_id: 1263182 + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + version_id: d6TyxbX + shortlink: https://sg.run/Ro1g + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jose + - jwt + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + symbolic_propagation: true + patterns: + - pattern-inside: "$JOSE = require(\"jose\");\n...\n" + - pattern-either: + - pattern-inside: "var {JWT} = $JOSE;\n...\n" + - pattern-inside: "var {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWK, JWT} = $JOSE;\n...\n" + - pattern-either: + - pattern: "JWT.verify($P, \"...\", ...);\n" + - pattern: "JWT.sign($P, \"...\", ...);\n" + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: "$JWT.sign($P, JWK.asKey(\"...\"), ...);\n" + severity: WARNING +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9294 + rule_id: 5rUOGN + rv_id: 1263183 + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + version_id: ZRTKAyb + shortlink: https://sg.run/AvRL + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jose + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nvar $T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\n$T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nJWT.verify($P, JWK.None,...);\n" + severity: ERROR +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9300 + rule_id: WAUon7 + rv_id: 1263189 + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + version_id: gETB75D + shortlink: https://sg.run/4xN9 + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jwt + - javascript + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$JWT = require(\"jsonwebtoken\")\n...\n" + - pattern-inside: "import $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import * as $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import {...,$JWT,...} from \"jsonwebtoken\"\n...\n" + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,$VALUE,...);\n" + - pattern-inside: "$JWT.verify($DATA,$VALUE,...);\n" + - focus-metavariable: $VALUE + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,\"...\",...);\n" + - pattern-inside: "$JWT.verify($DATA,\"...\",...);\n" + severity: WARNING +- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9301 + rule_id: 0oU53g + rv_id: 1263190 + url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + version_id: QkTGqQo + shortlink: https://sg.run/PJXv + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "$JWT = require(\"jsonwebtoken\");\n...\n" + - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) + severity: ERROR +- id: javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + languages: + - javascript + - typescript + message: Detected the decoding of a JWT token without a verify step. JWT tokens must be verified before use, otherwise + the token's integrity is unknown. This means a malicious actor could forge a JWT token with any claims. Set 'verify' + to `true` before using the token. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-287: Improper Authentication' + - 'CWE-345: Insufficient Verification of Data Authenticity' + - 'CWE-347: Improper Verification of Cryptographic Signature' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A07:2021 - Identification and Authentication Failures + - A02:2025 - Security Misconfiguration + - A07:2025 - Authentication Failures + references: + - https://www.npmjs.com/package/jwt-simple + - https://cwe.mitre.org/data/definitions/287 + - https://cwe.mitre.org/data/definitions/345 + - https://cwe.mitre.org/data/definitions/347 + semgrep.dev: + rule: + origin: community + r_id: 120561 + rule_id: r6UyNLy + rv_id: 1263191 + url: + https://semgrep.dev/playground/r/3ZT4Xxv/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + version_id: 3ZT4Xxv + shortlink: https://sg.run/zdjod + source: https://semgrep.dev/r/javascript.jwt-simple.security.jwt-simple-noverify.jwt-simple-noverify + subcategory: + - vuln + technology: + - jwt-simple + - jwt + vulnerability_class: + - Cryptographic Issues + - Improper Authentication + patterns: + - pattern-inside: "$JWT = require('jwt-simple');\n...\n" + - pattern: $JWT.decode($TOKEN, $SECRET, $NOVERIFY, ...) + - metavariable-pattern: + metavariable: $NOVERIFY + patterns: + - pattern-either: + - pattern: "true\n" + - pattern: "\"...\"\n" + severity: ERROR +- id: javascript.lang.security.audit.code-string-concat.code-string-concat + languages: + - javascript + - typescript + message: Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can + lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever + possible. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval + - https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback + - https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/ + - https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html + semgrep.dev: + rule: + origin: community + r_id: 13023 + rule_id: DbUKEz + rv_id: 1263192 + url: + https://semgrep.dev/playground/r/44TEjYX/javascript.lang.security.audit.code-string-concat.code-string-concat + version_id: 44TEjYX + shortlink: https://sg.run/96Yk + source: https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat + subcategory: + - vuln + technology: + - node.js + - Express + - Next.js + vulnerability_class: + - Code Injection + mode: taint + options: + interfile: true + pattern-sinks: + - patterns: + - pattern: "eval(...)\n" + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - patterns: + - pattern-either: + - pattern-inside: "import { ...,$IMPORT,... } from 'next/router'\n...\n" + - pattern-inside: "import $IMPORT from 'next/router';\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$ROUTER = $IMPORT()\n...\n" + - pattern-either: + - pattern-inside: "const { ...,$PROPS,... } = $ROUTER.query\n...\n" + - pattern-inside: "var { ...,$PROPS,... } = $ROUTER.query\n...\n" + - pattern-inside: "let { ...,$PROPS,... } = $ROUTER.query\n...\n" + - focus-metavariable: $PROPS + - patterns: + - pattern-inside: "$ROUTER = $IMPORT()\n...\n" + - pattern: "$ROUTER.query.$VALUE \n" + - patterns: + - pattern: $IMPORT().query.$VALUE + severity: ERROR +- id: javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + languages: + - javascript + - typescript + message: "Detected SQL statement that is tainted by `$REQ` object. This could lead to SQL injection if the variable is user-controlled + and not properly sanitized. In order to prevent SQL injection, it is recommended to use parameterized queries or prepared + statements. An example of parameterized queries like so: `knex.raw('SELECT $1 from table', [userinput])` can help prevent + SQLi." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://knexjs.org/#Builder-fromRaw + - https://knexjs.org/#Builder-whereRaw + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 18257 + rule_id: d8UKLD + rv_id: 1263205 + url: https://semgrep.dev/playground/r/l4TJRey/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + version_id: l4TJRey + shortlink: https://sg.run/l9eE + source: https://semgrep.dev/r/javascript.lang.security.audit.sqli.node-knex-sqli.node-knex-sqli + subcategory: + - vuln + technology: + - express + - nodejs + - knex + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern: parseInt(...) + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern-inside: $KNEX.fromRaw($QUERY, ...) + - pattern-inside: $KNEX.whereRaw($QUERY, ...) + - pattern-inside: $KNEX.raw($QUERY, ...) + - pattern-either: + - pattern-inside: "require('knex')\n...\n" + - pattern-inside: "import 'knex'\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options) + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: WARNING +- id: javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + languages: + - javascript + - typescript + message: Detected use of dynamic execution of JavaScript which may come from user-input, which can lead to + Cross-Site-Scripting (XSS). Where possible avoid including user-input in functions which dynamically execute + user-input. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval! + semgrep.dev: + rule: + origin: community + r_id: 9315 + rule_id: yyUngo + rv_id: 1263214 + url: + https://semgrep.dev/playground/r/WrTqKkJ/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + version_id: WrTqKkJ + shortlink: https://sg.run/6nwK + source: https://semgrep.dev/r/javascript.lang.security.detect-eval-with-expression.detect-eval-with-expression + source-rule-url: + https://github.com/nodesecurity/eslint-plugin-security/blob/master/rules/detect-eval-with-expression.js + subcategory: + - vuln + technology: + - javascript + vulnerability_class: + - Code Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: location.href = $FUNC(...) + - pattern: location.hash = $FUNC(...) + - pattern: location.search = $FUNC(...) + - pattern: $WINDOW. ... .location.href = $FUNC(...) + - pattern: $WINDOW. ... .location.hash = $FUNC(...) + - pattern: $WINDOW. ... .location.search = $FUNC(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval(<... $SINK ...>) + - pattern: window.eval(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>) + - pattern: new Function(<... $SINK ...>)(...) + - pattern: setTimeout(<... $SINK ...>,...) + - pattern: setInterval(<... $SINK ...>,...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "$PROP = new URLSearchParams($WINDOW. ... .location.search).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams(location.search).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams($WINDOW. ... .location.hash.substring(1)).get('...')\n ...\n" + - pattern-inside: "$PROP = new URLSearchParams(location.hash.substring(1)).get('...')\n ...\n" + - focus-metavariable: $PROP + - patterns: + - pattern-either: + - pattern-inside: "$PROPS = new URLSearchParams($WINDOW. ... .location.search)\n ...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.search)\n ...\n" + - pattern-inside: "$PROPS = new\nURLSearchParams($WINDOW. ... .location.hash.substring(1))\n ...\n" + - pattern-inside: "$PROPS = new URLSearchParams(location.hash.substring(1))\n...\n" + - pattern: $PROPS.get('...') + - focus-metavariable: $PROPS + - patterns: + - pattern-either: + - pattern: location.href + - pattern: location.hash + - pattern: location.search + - pattern: $WINDOW. ... .location.href + - pattern: $WINDOW. ... .location.hash + - pattern: $WINDOW. ... .location.search + severity: WARNING +- id: javascript.node-crypto.security.aead-no-final.aead-no-final + languages: + - javascript + - typescript + message: The 'final' call of a Decipher object checks the authentication tag in a mode for authenticated encryption. + Failing to call 'final' will invalidate all integrity guarantees of the released ciphertext. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nodejs.org/api/crypto.html#deciphersetauthtagbuffer-encoding + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 146569 + rule_id: 2ZUz884 + rv_id: 1263222 + url: https://semgrep.dev/playground/r/zyTb2X0/javascript.node-crypto.security.aead-no-final.aead-no-final + version_id: zyTb2X0 + shortlink: https://sg.run/r6EEA + source: https://semgrep.dev/r/javascript.node-crypto.security.aead-no-final.aead-no-final + subcategory: + - vuln + technology: + - node-crypto + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)\n...\n$DECIPHER.update(...)\n" + - pattern-not-inside: "$DECIPHER = $CRYPTO.createDecipheriv('$ALGO', ...)\n...\n$DECIPHER.final(...)\n" + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm|-ccm|-ocb|chacha20-poly1305)$ + severity: ERROR +- id: javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + languages: + - javascript + - typescript + message: The call to 'createDecipheriv' with the Galois Counter Mode (GCM) mode of operation is missing an expected + authentication tag length. If the expected authentication tag length is not specified or otherwise checked, the + application might be tricked into verifying a shorter-than-expected authentication tag. This can be abused by an + attacker to spoof ciphertexts or recover the implicit authentication key of GCM, allowing arbitrary forgeries. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-310: CWE CATEGORY: Cryptographic Issues' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.securesystems.de/blog/forging_ciphertexts_under_Galois_Counter_Mode_for_the_Node_js_crypto_module/ + - https://nodejs.org/api/crypto.html#cryptocreatedecipherivalgorithm-key-iv-options + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 146571 + rule_id: j2UgPP3 + rv_id: 1263223 + url: + https://semgrep.dev/playground/r/pZT03qd/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + version_id: pZT03qd + shortlink: https://sg.run/NbGG1 + source: https://semgrep.dev/r/javascript.node-crypto.security.gcm-no-tag-length.gcm-no-tag-length + subcategory: + - vuln + technology: + - node-crypto + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$CRYPTO.createDecipheriv('$ALGO', $KEY, $IV)\n" + - metavariable-regex: + metavariable: $ALGO + regex: .*(-gcm)$ + severity: ERROR +- id: javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9333 + rule_id: QrUzq6 + rv_id: 1263225 + url: + https://semgrep.dev/playground/r/X0TzyoE/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + version_id: X0TzyoE + shortlink: https://sg.run/vz70 + source: https://semgrep.dev/r/javascript.passport-jwt.security.passport-hardcode.hardcoded-passport-secret + subcategory: + - vuln + technology: + - jwt + - nodejs + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$F = require(\"$I\").Strategy\n...\n" + - pattern-inside: "$F = require(\"$I\")\n...\n" + - pattern-inside: "import { $STRAT as $F } from '$I'\n...\n" + - pattern-inside: "import $F from '$I'\n...\n" + - metavariable-regex: + metavariable: $I + regex: (passport-.*) + - pattern-inside: "new $F($VALUE,...)\n" + - focus-metavariable: $VALUE + pattern-sources: + - by-side-effect: true + patterns: + - pattern-either: + - pattern: "{..., clientSecret: \"...\", ...}\n" + - pattern: "{..., secretOrKey: \"...\", ...}\n" + - pattern: "{..., consumerSecret: \"...\", ...}\n" + - patterns: + - pattern-inside: "$OBJ = {}\n...\n" + - pattern-either: + - pattern: "$OBJ.clientSecret = \"...\"\n" + - pattern: "$OBJ.secretOrKey = \"...\"\n" + - pattern: "$OBJ.consumerSecret = \"...\"\n" + - pattern: $OBJ + - patterns: + - pattern-inside: "$SECRET = '...'\n...\n" + - pattern-either: + - pattern: "{..., clientSecret: $SECRET, ...}\n" + - pattern: "{..., secretOrKey: $SECRET, ...}\n" + - pattern: "{..., consumerSecret: $SECRET, ...}\n" + - patterns: + - pattern-inside: "$SECRET = '...'\n...\n" + - pattern-either: + - pattern-inside: "$VALUE = {..., clientSecret: $SECRET, ...}\n...\n" + - pattern-inside: "$VALUE = {..., secretOrKey: $SECRET, ...}\n...\n" + - pattern-inside: "$VALUE = {..., consumerSecret: $SECRET, ...}\n...\n" + - pattern: $VALUE + severity: WARNING +- id: javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + languages: + - javascript + - typescript + message: Detected a sequelize statement that is tainted by user-input. This could lead to SQL injection if the + variable is user-controlled and is not properly sanitized. In order to prevent SQL injection, it is recommended to + use parameterized queries or prepared statements. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://sequelize.org/docs/v6/core-concepts/raw-queries/#replacements + semgrep.dev: + rule: + origin: community + r_id: 22085 + rule_id: yyU0GX + rv_id: 1263241 + url: + https://semgrep.dev/playground/r/nWT2Llx/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + version_id: nWT2Llx + shortlink: https://sg.run/gjoe + source: + https://semgrep.dev/r/javascript.sequelize.security.audit.sequelize-injection-express.express-sequelize-injection + subcategory: + - vuln + technology: + - express + vulnerability_class: + - SQL Injection + mode: taint + options: + interfile: true + pattern-sanitizers: + - pattern-either: + - pattern: parseInt(...) + - pattern: $FUNC. ... .hash(...) + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sequelize.query($QUERY,...) + - pattern: $DB.sequelize.query($QUERY,...) + - focus-metavariable: $QUERY + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: function ... ($REQ, $RES) {...} + - pattern-inside: function ... ($REQ, $RES, $NEXT) {...} + - patterns: + - pattern-either: + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES) {...}) + - pattern-inside: $APP.$METHOD(..., function $FUNC($REQ, $RES, $NEXT) {...}) + - metavariable-regex: + metavariable: $METHOD + regex: ^(get|post|put|head|delete|options)$ + - pattern-either: + - pattern: $REQ.query + - pattern: $REQ.body + - pattern: $REQ.params + - pattern: $REQ.cookies + - pattern: $REQ.headers + - pattern: $REQ.files.$ANYTHING.data.toString('utf8') + - pattern: $REQ.files.$ANYTHING['data'].toString('utf8') + - patterns: + - pattern-either: + - pattern-inside: "({ $REQ }: Request,$RES: Response, $NEXT: NextFunction) =>\n{...}\n" + - pattern-inside: "({ $REQ }: Request,$RES: Response) => {...}\n" + - focus-metavariable: $REQ + - pattern-either: + - pattern: params + - pattern: query + - pattern: cookies + - pattern: headers + - pattern: body + - pattern: files.$ANYTHING.data.toString('utf8') + - pattern: files.$ANYTHING['data'].toString('utf8') + severity: ERROR +- id: json.aws.security.public-s3-bucket.public-s3-bucket + languages: + - json + message: Detected public S3 bucket. This policy allows anyone to have some kind of access to the bucket. The exact + level of access and types of actions allowed will depend on the configuration of bucket policy and ACLs. Please + review the bucket configuration to make sure they are set with intended values. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html + semgrep.dev: + rule: + origin: community + r_id: 13413 + rule_id: 7KUpLy + rv_id: 1263254 + url: https://semgrep.dev/playground/r/RGT0Ld0/json.aws.security.public-s3-bucket.public-s3-bucket + version_id: RGT0Ld0 + shortlink: https://sg.run/lxv5 + source: https://semgrep.dev/r/json.aws.security.public-s3-bucket.public-s3-bucket + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "$BUCKETNAME: {\n \"Type\": \"AWS::S3::Bucket\",\n \"Properties\": {\n ...,\n },\n ...,\n}\n" + - pattern-either: + - pattern: "\"PublicAccessBlockConfiguration\": {\n ...,\n \"RestrictPublicBuckets\": false,\n ...,\n },\n" + - pattern: "\"PublicAccessBlockConfiguration\": {\n ...,\n \"IgnorePublicAcls\": false,\n ...,\n },\n" + - pattern: "\"PublicAccessBlockConfiguration\": {\n ...,\n \"BlockPublicAcls\": false,\n ...,\n },\n" + - pattern: "\"PublicAccessBlockConfiguration\": {\n ...,\n \"BlockPublicPolicy\": false,\n ...,\n },\n" + severity: WARNING +- id: json.aws.security.public-s3-policy-statement.public-s3-policy-statement + languages: + - json + message: Detected public S3 bucket policy. This policy allows anyone to access certain properties of or items in the + bucket. Do not do this unless you will never have sensitive data inside the bucket. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.aws.amazon.com/AmazonS3/latest/dev/WebsiteAccessPermissionsReqd.html + semgrep.dev: + rule: + origin: community + r_id: 9358 + rule_id: 9AU1br + rv_id: 1263255 + url: + https://semgrep.dev/playground/r/A8Tgdxq/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + version_id: A8Tgdxq + shortlink: https://sg.run/Yv1d + source: https://semgrep.dev/r/json.aws.security.public-s3-policy-statement.public-s3-policy-statement + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + pattern: "{\n \"Effect\": \"Allow\",\n \"Principal\": \"*\",\n \"Resource\": [\n ..., \"=~/arn:aws:s3.*/\", ...\n\ + \ ],\n ...\n}\n" + severity: WARNING +- id: json.aws.security.wildcard-assume-role.wildcard-assume-role + languages: + - json + message: 'Detected wildcard access granted to sts:AssumeRole. This means anyone with your AWS account ID and the name of + the role can assume the role. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::root`.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + semgrep.dev: + rule: + origin: community + r_id: 15138 + rule_id: JDULx5 + rv_id: 1263256 + url: https://semgrep.dev/playground/r/BjTkZoy/json.aws.security.wildcard-assume-role.wildcard-assume-role + version_id: BjTkZoy + shortlink: https://sg.run/7YEZ + source: https://semgrep.dev/r/json.aws.security.wildcard-assume-role.wildcard-assume-role + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "\"Statement\": [...]\n" + - pattern-inside: "{..., \"Effect\": \"Allow\", ..., \"Action\": \"sts:AssumeRole\", ...}\n" + - pattern: "\"Principal\": {..., \"AWS\": \"*\", ...}\n" + severity: ERROR +- id: kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + languages: + - kotlin + message: A secret is hard-coded in the application. Secrets stored in source code, such as credentials, identifiers, + and other types of sensitive data, can be leaked and used by internal or external malicious actors. It is + recommended to rotate the secret and retrieve them from a secure secret vault or Hardware Security Module (HSM), + alternatively environment variables can be used if allowed by your company policy. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2020-top25: true + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 137856 + rule_id: ReUD6Kg + rv_id: 1263257 + url: + https://semgrep.dev/playground/r/DkTRbLX/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + version_id: DkTRbLX + shortlink: https://sg.run/qN29x + source: https://semgrep.dev/r/kotlin.gradle.security.build-gradle-password-hardcoded.build-gradle-password-hardcoded + source_rule_url: https://semgrep.dev/playground/r/d8Ur5BA/achufistov6_personal_org.build-gradle-password-hardcoded + subcategory: + - vuln + technology: + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + symbolic_propagation: true + paths: + include: + - '*build.gradle.kts' + patterns: + - pattern-either: + - pattern: '$PASS = env[...] ?: $VALUE' + - metavariable-regex: + metavariable: $PASS + regex: (password|pass|passwd|loginPassword) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^[A-Za-z0-9/+=]+$ + severity: WARNING +- id: kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + languages: + - kt + message: Detected anonymous LDAP bind. This permits anonymous users to execute LDAP statements. Consider enforcing + authentication for LDAP. See https://docs.oracle.com/javase/tutorial/jndi/ldap/auth_mechs.html for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-287: Improper Authentication' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 15125 + rule_id: v8U9Q7 + rv_id: 1263258 + url: https://semgrep.dev/playground/r/WrTqKgJ/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + version_id: WrTqKgJ + shortlink: https://sg.run/rY2n + source: https://semgrep.dev/r/kotlin.lang.security.anonymous-ldap-bind.anonymous-ldap-bind + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#LDAP_ANONYMOUS + subcategory: + - vuln + technology: + - kotlin + vulnerability_class: + - Improper Authentication + pattern: "$ENV.put($CTX.SECURITY_AUTHENTICATION, \"none\")\n...\n$DCTX = InitialDirContext($ENV, ...)\n" + severity: WARNING +- id: kotlin.lang.security.ecb-cipher.ecb-cipher + languages: + - kt + message: Cipher in ECB mode is detected. ECB mode produces the same output for the same input each time which allows + an attacker to intercept and replay the data. Further, ECB mode does not provide any integrity checking. See + https://find-sec-bugs.github.io/bugs.htm#CIPHER_INTEGRITY. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 14696 + rule_id: DbU1Zd + rv_id: 1263263 + url: https://semgrep.dev/playground/r/YDTZexg/kotlin.lang.security.ecb-cipher.ecb-cipher + version_id: YDTZexg + shortlink: https://sg.run/DzLj + source: https://semgrep.dev/r/kotlin.lang.security.ecb-cipher.ecb-cipher + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#ECB_MODE + subcategory: + - vuln + technology: + - kotlin + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "val $VAR : Cipher = $CIPHER.getInstance($MODE)\n" + - pattern: "var $VAR : Cipher = $CIPHER.getInstance($MODE)\n" + - pattern: "val $VAR = $CIPHER.getInstance($MODE)\n" + - pattern: "var $VAR = $CIPHER.getInstance($MODE)\n" + - metavariable-regex: + metavariable: $MODE + regex: .*ECB.* + severity: WARNING +- id: kotlin.lang.security.no-null-cipher.no-null-cipher + languages: + - kt + - scala + message: 'NullCipher was detected. This will not encrypt anything; the cipher text will be the same as the plain text. Use + a valid, secure cipher: Cipher.getInstance("AES/CBC/PKCS7PADDING"). See https://owasp.org/www-community/Using_the_Java_Cryptographic_Extensions + for more information.' + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 14698 + rule_id: 0oU2Yy + rv_id: 1263265 + url: https://semgrep.dev/playground/r/o5TbDPj/kotlin.lang.security.no-null-cipher.no-null-cipher + version_id: o5TbDPj + shortlink: https://sg.run/0ywb + source: https://semgrep.dev/r/kotlin.lang.security.no-null-cipher.no-null-cipher + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#NULL_CIPHER + subcategory: + - vuln + technology: + - kotlin + vulnerability_class: + - Cryptographic Issues + pattern: NullCipher(...) + severity: WARNING +- id: kotlin.lang.security.use-of-md5.use-of-md5 + languages: + - kt + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 14700 + rule_id: qNUXPj + rv_id: 1263267 + url: https://semgrep.dev/playground/r/pZT03Jd/kotlin.lang.security.use-of-md5.use-of-md5 + version_id: pZT03Jd + shortlink: https://sg.run/4eQx + source: https://semgrep.dev/r/kotlin.lang.security.use-of-md5.use-of-md5 + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_MD5 + subcategory: + - vuln + technology: + - kotlin + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: "java.security.MessageDigest.getInstance(\"MD5\")\n" + - pattern: "org.apache.commons.codec.digest.DigestUtils.getMd5Digest()\n" + severity: WARNING +- id: kotlin.lang.security.use-of-sha1.use-of-sha1 + languages: + - kt + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 15127 + rule_id: ZqUOdd + rv_id: 1263268 + url: https://semgrep.dev/playground/r/2KTv2XZ/kotlin.lang.security.use-of-sha1.use-of-sha1 + version_id: 2KTv2XZ + shortlink: https://sg.run/N1pp + source: https://semgrep.dev/r/kotlin.lang.security.use-of-sha1.use-of-sha1 + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#WEAK_MESSAGE_DIGEST_SHA1 + subcategory: + - vuln + technology: + - kotlin + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern: "$VAR = $MD.getInstance(\"$ALGO\")\n" + - metavariable-regex: + metavariable: $ALGO + regex: (SHA1|SHA-1) + - pattern: "$DU.getSha1Digest().digest(...)\n" + severity: WARNING +- id: kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + languages: + - kt + message: RSA keys should be at least 2048 bits based on NIST recommendation. + metadata: + asvs: + control_id: 6.2.5 Insecure Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Cryptographic_Storage_Cheat_Sheet.html#algorithms + semgrep.dev: + rule: + origin: community + r_id: 15128 + rule_id: nJUZNL + rv_id: 1263269 + url: https://semgrep.dev/playground/r/X0TzypE/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + version_id: X0TzypE + shortlink: https://sg.run/krq7 + source: https://semgrep.dev/r/kotlin.lang.security.weak-rsa.use-of-weak-rsa-key + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#RSA_KEY_SIZE + subcategory: + - audit + technology: + - kotlin + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "$KEY = $G.getInstance(\"RSA\")\n...\n$KEY.initialize($BITS)\n" + - metavariable-comparison: + comparison: $BITS < 2048 + metavariable: $BITS + severity: WARNING +- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + languages: + - generic + message: 'This bunfig.toml does not set a minimum release age or sets it too low. Newly published packages can be malicious + or unstable. Add `minimumReleaseAge = 604800` under the `[install]` section to wait 7 days before resolving newly published + package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://bun.sh/docs/runtime/bunfig + semgrep.dev: + rule: + origin: community + r_id: 291646 + rule_id: oqUyJOb + rv_id: 1423385 + url: + https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + version_id: BjTyRe5 + shortlink: https://sg.run/JqPrR + source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + subcategory: + - audit + technology: + - bun + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/bunfig.toml' + - '**/.bunfig.toml' + pattern-either: + - patterns: + - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*minimumReleaseAge) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: minimumReleaseAge\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 604800 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ + severity: MEDIUM +- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + languages: + - yaml + message: 'This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. + Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before + proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown + semgrep.dev: + rule: + origin: community + r_id: 291647 + rule_id: zdUArOL + rv_id: 1423386 + url: + https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + version_id: DkTwEGl + shortlink: https://sg.run/5WvGK + source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + subcategory: + - audit + technology: + - dependabot + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.github/dependabot.yml' + - '**/.github/dependabot.yaml' + pattern-either: + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern: "- package-ecosystem: $ECOSYSTEM\n ...\n" + - pattern-not: "- package-ecosystem: $ECOSYSTEM\n ...\n cooldown:\n ...\n ...\n" + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern-regex: default-days\s*:\s*(?P\d+) + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern: "cooldown:\n default-days: $DAYS\n" + - metavariable-regex: + metavariable: $DAYS + regex: ^\D + - focus-metavariable: $DAYS + severity: MEDIUM +- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + languages: + - generic + message: 'This .npmrc does not set a minimum release age or sets it too low. Newly published packages can be malicious or + unstable. Add `min-release-age = 7` to wait 7 days before resolving newly published package versions. Added in: v11.10 + Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ + - https://github.com/npm/cli/pull/8965 + semgrep.dev: + rule: + origin: community + r_id: 291648 + rule_id: pKU6A82 + rv_id: 1423387 + url: + https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + version_id: WrT7LdL + shortlink: https://sg.run/GRo1z + source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + subcategory: + - audit + technology: + - npm + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.npmrc' + pattern-either: + - patterns: + - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) + - pattern-not-regex: min-release-age + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: min-release-age\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 7 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)min-release-age\s*=\s*$ + severity: MEDIUM +- id: package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + languages: + - yaml + message: 'Missing or incorrect blockExoticSubdeps. Set `blockExoticSubdeps: true` to transitive dependencies from being + installed from untrusted sources. Added in: v10.26.0 Reference: https://pnpm.io/settings#blockexoticsubdeps' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://pnpm.io/settings#blockexoticsubdeps + semgrep.dev: + rule: + origin: community + r_id: 291649 + rule_id: 2ZUQEZ5 + rv_id: 1423388 + url: + https://semgrep.dev/playground/r/0bTGnwj/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + version_id: 0bTGnwj + shortlink: https://sg.run/RrWRv + source: + https://semgrep.dev/r/package_managers.pnpm.pnpm-block-exotic-sub-dependencies.pnpm-block-exotic-sub-dependencies + subcategory: + - audit + technology: + - pnpm + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^blockExoticSubdeps\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: "blockExoticSubdeps: $VAL\n" + - metavariable-regex: + metavariable: $VAL + regex: ^(?!true$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*blockExoticSubdeps\s*:\s*$ + severity: MEDIUM +- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + languages: + - yaml + message: 'This pnpm workspace configuration does not set a minimum release age. Newly published packages can be malicious + or unstable. Add `minimumReleaseAge: 10080` (minutes) to wait at least seven days before installing newly published package + versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://pnpm.io/settings#minimumreleaseage + semgrep.dev: + rule: + origin: community + r_id: 291650 + rule_id: X5Uwn1n + rv_id: 1423389 + url: + https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + version_id: K3TgxrW + shortlink: https://sg.run/Aj0o0 + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + subcategory: + - audit + technology: + - pnpm + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 10080 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern: "minimumReleaseAge: $AGE\n" + - metavariable-regex: + metavariable: $AGE + regex: ^\D + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ + severity: MEDIUM +- id: package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + languages: + - yaml + message: 'Missing or incorrect trustPolicy. Set `trustPolicy: no-downgrade` to prevent malicious package updates from downgrading + security settings. Added in: v10.21.0 Reference: https://pnpm.io/settings#trustpolicy' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://pnpm.io/settings#minimumreleaseage + semgrep.dev: + rule: + origin: community + r_id: 291651 + rule_id: j2U6J8N + rv_id: 1423390 + url: https://semgrep.dev/playground/r/qkTvDQn/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + version_id: qkTvDQn + shortlink: https://sg.run/B2Kz7 + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-trust-policy.pnpm-trust-policy + subcategory: + - audit + technology: + - pnpm + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^trustPolicy\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern: "trustPolicy: $VAL\n" + - metavariable-regex: + metavariable: $VAL + regex: ^(?!no-downgrade$).+ + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^\s*trustPolicy\s*:\s*$ + severity: MEDIUM +- id: package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + languages: + - generic + message: 'This poetry.toml does not set a dependency cooldown via `solver.min-release-age`. Without a cooldown, Poetry may + resolve newly published package versions that have not yet been vetted by the community. Supply chain attacks frequently + involve publishing a malicious version of a popular package and waiting for it to be pulled in — most are detected and + removed within days. Set `min-release-age = 7` under `[solver]` to require that package versions are at least 7 days old + before they are considered during dependency resolution. Added in: v2.4.0' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://python-poetry.org/docs/configuration/#solvermin-release-age + semgrep.dev: + rule: + origin: community + r_id: 309390 + rule_id: kxUjBPy + rv_id: 1443453 + url: + https://semgrep.dev/playground/r/X0TYPX6/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + version_id: X0TYPX6 + shortlink: https://sg.run/JqnYZ + source: + https://semgrep.dev/r/package_managers.poetry.poetry-missing-solver-min-release-age.poetry-missing-solver-min-release-age + subcategory: + - audit + technology: + - poetry + - python + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/poetry.toml' + - '**/config.toml' + pattern-either: + - pattern-regex: (?m)^\[solver\]\n(?:^(?!min-release-age|\[|---).*\n)*(?=^\[|^---|\z) + - pattern-regex: (?ms)^\[solver\](?:[^\[]*?)min-release-age\s*=\s*(?P"[^"]*"|[0-6](?:\s|#|$)|false) + severity: MEDIUM +- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + languages: + - json + message: 'This Renovate configuration does not set a minimum release age. Newly published packages can be malicious or unstable. + Add `"minimumReleaseAge": "7 days"` within a `packageRules` entry to wait 7 days before proposing updates to newly published + package versions. Set `"minimumReleaseAge": false` to set an exception for minimal release age for the package rule. Added + in: v42' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.renovatebot.com/configuration-options/#minimumreleaseage + semgrep.dev: + rule: + origin: community + r_id: 291652 + rule_id: 10UbQrX + rv_id: 1443454 + url: + https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + version_id: jQT1KAX + shortlink: https://sg.run/D8l2q + source: + https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + subcategory: + - audit + technology: + - renovate + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/renovate.json' + - '**/renovate.json5' + - '**/.renovaterc' + - '**/.renovaterc.json' + - '**/.renovaterc.json5' + pattern-either: + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern-either: + - pattern: "{ ..., \"matchPackageNames\": [...], ... }\n" + - pattern: "{ ..., \"matchPackagePatterns\": [...], ... }\n" + - pattern: "{ ..., \"matchDepTypes\": [...], ... }\n" + - pattern-not: "{\n ...,\n \"minimumReleaseAge\": $AGE,\n ...\n}\n" + - pattern-not: "{\n ...,\n \"minimumReleaseAge\": false,\n ...\n}\n" + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' + - metavariable-comparison: + comparison: int($AGE) < 7 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern: "\"minimumReleaseAge\": \"$AGE\"\n" + - metavariable-regex: + metavariable: $AGE + regex: ^(?!\d+ days?$) + - focus-metavariable: $AGE + severity: MEDIUM +- id: package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + languages: + - ruby + message: 'A Gemfile `source` declaration without a `cooldown` (or with a cooldown below 7 days) allows Bundler to resolve + newly published gem versions immediately, before the community has had time to detect malicious releases. The May 2026 + RubyGems supply-chain attack demonstrated that threat actors can push compromised gem versions and have them automatically + pulled into builds within minutes. Add `cooldown: 7` to each public source declaration so Bundler ignores gem versions + published within the last 7 days during dependency resolution (e.g. `source "https://rubygems.org", cooldown: 7`). If + you operate an internal or private registry where the supply-chain risk is lower, use `cooldown: 0` as an explicit bypass. + Note: this feature requires Bundler >= 4.0.13. Cooldown only applies during `bundle update` and `bundle add`; `bundle + install` with an existing lockfile is unaffected.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://blog.rubygems.org/2026/06/03/cooldown-let-new-gems-be-vetted.html + semgrep.dev: + rule: + origin: community + r_id: 309391 + rule_id: wdUzPbP + rv_id: 1443455 + url: + https://semgrep.dev/playground/r/1QTEjAN/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + version_id: 1QTEjAN + shortlink: https://sg.run/5Wlkl + source: + https://semgrep.dev/r/package_managers.ruby.bundler-gemfile-missing-cooldown.bundler-gemfile-missing-cooldown + subcategory: + - audit + technology: + - bundler + - ruby + vulnerability_class: + - Insecure Configuration + paths: + exclude: + - '**/vendor/**' + - '**/.bundle/**' + include: + - '**/Gemfile' + - '**/gems.rb' + pattern-either: + - patterns: + - pattern: source "...", ... + - pattern-not: 'source "...", ..., cooldown: $N, ...' + - patterns: + - pattern: 'source "...", ..., cooldown: $N, ...' + - metavariable-comparison: + comparison: $N > 0 and $N < 7 + metavariable: $N + - focus-metavariable: $N + severity: MEDIUM +- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + languages: + - generic + message: 'This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious + or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package + versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + semgrep.dev: + rule: + origin: community + r_id: 291653 + rule_id: 9AUo6vE + rv_id: 1501839 + url: + https://semgrep.dev/playground/r/kbT3B1J/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + version_id: kbT3B1J + shortlink: https://sg.run/WeY0Z + source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + subcategory: + - audit + technology: + - uv + - python + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pyproject.toml' + - '**/uv.toml' + pattern-either: + - patterns: + - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*exclude-newer) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P\d+)\s*d(?:ays?)?" + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" + - metavariable-regex: + metavariable: $VAL + regex: + (?i)^(?!\d+\s*d(?:ays?)?\b)(?!\d+\s*(?:weeks?|wks?|w|months?|mos?|mo|years?|yrs?|y)\b)(?!P[^Tt]*[WMY])(?!P(?:[7-9]|[1-9]\d+)D\b) + - focus-metavariable: $VAL + severity: MEDIUM +- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + languages: + - yaml + message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly published packages can be malicious + or unstable. Add `npmMinimalAgeGate: "7d"` to wait 7 days before resolving newly published package versions. Added in: + 4.10 Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate + semgrep.dev: + rule: + origin: community + r_id: 291654 + rule_id: yyUBeEz + rv_id: 1423393 + url: + https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + version_id: JdTnXlj + shortlink: https://sg.run/0gvNq + source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + subcategory: + - audit + technology: + - yarn + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.yarnrc.yml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) + - metavariable-regex: + metavariable: $VAL + regex: ^(?!['"]?\d+d['"]?$) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ + severity: MEDIUM +- id: php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + languages: + - php + message: '`$QUERY` Detected string concatenation with a non-literal variable in a Doctrine QueryBuilder method. This could + lead to SQL injection if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, + use parameterized queries or prepared statements instead.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.doctrine-project.org/projects/doctrine-dbal/en/current/reference/query-builder.html#security-safely-preventing-sql-injection + - https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 13965 + rule_id: kxUw23 + rv_id: 1263271 + url: + https://semgrep.dev/playground/r/1QTypnG/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + version_id: 1QTypnG + shortlink: https://sg.run/jwDJ + source: https://semgrep.dev/r/php.doctrine.security.audit.doctrine-orm-dangerous-query.doctrine-orm-dangerous-query + subcategory: + - vuln + technology: + - doctrine + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $QUERY->add(...,$SINK,...) + - pattern: $QUERY->select(...,$SINK,...) + - pattern: $QUERY->addSelect(...,$SINK,...) + - pattern: $QUERY->delete(...,$SINK,...) + - pattern: $QUERY->update(...,$SINK,...) + - pattern: $QUERY->insert(...,$SINK,...) + - pattern: $QUERY->from(...,$SINK,...) + - pattern: $QUERY->join(...,$SINK,...) + - pattern: $QUERY->innerJoin(...,$SINK,...) + - pattern: $QUERY->leftJoin(...,$SINK,...) + - pattern: $QUERY->rightJoin(...,$SINK,...) + - pattern: $QUERY->where(...,$SINK,...) + - pattern: $QUERY->andWhere(...,$SINK,...) + - pattern: $QUERY->orWhere(...,$SINK,...) + - pattern: $QUERY->groupBy(...,$SINK,...) + - pattern: $QUERY->addGroupBy(...,$SINK,...) + - pattern: $QUERY->having(...,$SINK,...) + - pattern: $QUERY->andHaving(...,$SINK,...) + - pattern: $QUERY->orHaving(...,$SINK,...) + - pattern: $QUERY->orderBy(...,$SINK,...) + - pattern: $QUERY->addOrderBy(...,$SINK,...) + - pattern: $QUERY->set($SINK,...) + - pattern: $QUERY->setValue($SINK,...) + - pattern-either: + - pattern-inside: "$Q = $X->createQueryBuilder();\n...\n" + - pattern-inside: "$Q = new QueryBuilder(...);\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: sprintf(...) + - pattern: "\"...\".$SMTH\n" + severity: WARNING +- id: php.lang.security.assert-use.assert-use + languages: + - php + message: Calling assert with user input is equivalent to eval'ing. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/function.assert + - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/AssertsSniff.php + semgrep.dev: + rule: + origin: community + r_id: 9387 + rule_id: DbUpjk + rv_id: 1263272 + url: https://semgrep.dev/playground/r/9lT4bLx/php.lang.security.assert-use.assert-use + version_id: 9lT4bLx + shortlink: https://sg.run/3xXW + source: https://semgrep.dev/r/php.lang.security.assert-use.assert-use + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: assert($SINK, ...); + - pattern-not: assert("...", ...); + - pattern: $SINK + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + - patterns: + - pattern: "Route::$METHOD($ROUTENAME, function(..., $ARG, ...) { ... })\n" + - focus-metavariable: $ARG + severity: ERROR +- id: php.lang.security.audit.sha224-hash.sha224-hash + languages: + - php + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151751 + rule_id: AbU97EA + rv_id: 1263275 + url: https://semgrep.dev/playground/r/bZT53Jo/php.lang.security.audit.sha224-hash.sha224-hash + version_id: bZT53Jo + shortlink: https://sg.run/BYXqv + source: https://semgrep.dev/r/php.lang.security.audit.sha224-hash.sha224-hash + subcategory: + - audit + technology: + - php + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: hash('sha224', ...); + - pattern: hash('sha512/224', ...); + - pattern: hash('sha3-224', ...); + - pattern: hash_hmac('sha224', ...); + - pattern: hash_hmac('sha512/224', ...); + - pattern: hash_hmac('sha3-224', ...); + severity: WARNING +- id: php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + languages: + - php + message: SSL verification is disabled but should not be (currently CURLOPT_SSL_VERIFYPEER= $IS_VERIFIED) + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.saotn.org/dont-turn-off-curlopt_ssl_verifypeer-fix-php-configuration/ + semgrep.dev: + rule: + origin: community + r_id: 9389 + rule_id: 0oU5Xg + rv_id: 1263277 + url: https://semgrep.dev/playground/r/kbTzG9b/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + version_id: kbTzG9b + shortlink: https://sg.run/PJqv + source: https://semgrep.dev/r/php.lang.security.curl-ssl-verifypeer-off.curl-ssl-verifypeer-off + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - pattern: "$ARG = $IS_VERIFIED;\n...\ncurl_setopt(..., CURLOPT_SSL_VERIFYPEER, $ARG);\n" + - pattern: curl_setopt(..., CURLOPT_SSL_VERIFYPEER, $IS_VERIFIED) + - metavariable-regex: + metavariable: $IS_VERIFIED + regex: 0|false|null + severity: ERROR +- id: php.lang.security.deserialization.extract-user-data + languages: + - php + message: Do not call 'extract()' on user-controllable data. If you must, then you must also provide the EXTR_SKIP flag + to prevent overwriting existing variables. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://www.php.net/manual/en/function.extract.php#refsect1-function.extract-notes + semgrep.dev: + rule: + origin: community + r_id: 18259 + rule_id: nJUykq + rv_id: 1263278 + url: https://semgrep.dev/playground/r/w8TRovw/php.lang.security.deserialization.extract-user-data + version_id: w8TRovw + shortlink: https://sg.run/6bv1 + source: https://semgrep.dev/r/php.lang.security.deserialization.extract-user-data + subcategory: + - vuln + technology: + - php + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sanitizers: + - pattern: extract($VAR, EXTR_SKIP,...) + pattern-sinks: + - pattern: extract(...) + pattern-sources: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_FILES[...] + - pattern: $_POST[...] + severity: ERROR +- fix: echo htmlentities($...VARS); + id: php.lang.security.injection.echoed-request.echoed-request + languages: + - php + message: '`Echo`ing user input risks cross-site scripting vulnerability. You should use `htmlentities()` when showing data + to users.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 31707 + rule_id: BYUyyg + rv_id: 1263283 + url: https://semgrep.dev/playground/r/d6TyxE9/php.lang.security.injection.echoed-request.echoed-request + version_id: d6TyxE9 + shortlink: https://sg.run/Bqqb + source: https://semgrep.dev/r/php.lang.security.injection.echoed-request.echoed-request + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + pattern-sinks: + - pattern: echo $...VARS; + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + severity: ERROR +- fix: print(htmlentities($...VARS)); + id: php.lang.security.injection.printed-request.printed-request + languages: + - php + message: '`Printing user input risks cross-site scripting vulnerability. You should use `htmlentities()` when showing data + to users.' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/function.htmlentities.php + - https://www.php.net/manual/en/reserved.variables.request.php + - https://www.php.net/manual/en/reserved.variables.post.php + - https://www.php.net/manual/en/reserved.variables.get.php + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 128886 + rule_id: KxUvRBw + rv_id: 1263284 + url: https://semgrep.dev/playground/r/ZRTKAk4/php.lang.security.injection.printed-request.printed-request + version_id: ZRTKAk4 + shortlink: https://sg.run/QrxEJ + source: https://semgrep.dev/r/php.lang.security.injection.printed-request.printed-request + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: htmlentities(...) + - pattern: htmlspecialchars(...) + - pattern: strip_tags(...) + - pattern: isset(...) + - pattern: empty(...) + - pattern: esc_html(...) + - pattern: esc_attr(...) + - pattern: wp_kses(...) + - pattern: e(...) + - pattern: twig_escape_filter(...) + - pattern: xss_clean(...) + - pattern: html_escape(...) + - pattern: Html::escape(...) + - pattern: Xss::filter(...) + - pattern: escapeHtml(...) + - pattern: escapeHtml(...) + - pattern: escapeHtmlAttr(...) + pattern-sinks: + - pattern: print($...VARS); + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + severity: ERROR +- id: php.lang.security.injection.tainted-callable.tainted-callable + languages: + - php + message: Callable based on user input risks remote code execution. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.php.net/manual/en/language.types.callable.php + semgrep.dev: + rule: + origin: community + r_id: 141958 + rule_id: 0oULBKK + rv_id: 1263285 + url: https://semgrep.dev/playground/r/nWT2L5x/php.lang.security.injection.tainted-callable.tainted-callable + version_id: nWT2L5x + shortlink: https://sg.run/YGb33 + source: https://semgrep.dev/r/php.lang.security.injection.tainted-callable.tainted-callable + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $CALLABLE + - pattern-either: + - pattern-inside: $ARRAYITERATOR->uasort($CALLABLE) + - pattern-inside: $ARRAYITERATOR->uksort($CALLABLE) + - pattern-inside: $EVENTHTTP->setCallback($CALLABLE, ...) + - pattern-inside: $EVENTHTTPCONNECTION->setCloseCallback($CALLABLE, ...) + - pattern-inside: $EVLOOP->fork($CALLABLE, ...) + - pattern-inside: $EVLOOP->idle($CALLABLE, ...) + - pattern-inside: $EVLOOP->prepare($CALLABLE, ...) + - pattern-inside: $EVWATCHER->setCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setClientCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCompleteCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setCreatedCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setDataCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setExceptionCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setFailCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setStatusCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWarningCallback($CALLABLE) + - pattern-inside: $GEARMANCLIENT->setWorkloadCallback($CALLABLE) + - pattern-inside: $IMAGICK->setProgressMonitor($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->consumerHandler($CALLABLE) + - pattern-inside: $OAUTHPROVIDER->tokenHandler($CALLABLE) + - pattern-inside: $PDO->sqliteCreateCollation($NAME, $CALLABLE) + - pattern-inside: $PDOSTATEMENT->fetchAll(PDO::FETCH_FUNC, $CALLABLE) + - pattern-inside: $SQLITE3->createCollation($NAME, $CALLABLE) + - pattern-inside: $SQLITE3->setAuthorizer($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerCancelCallback($CALLABLE) + - pattern-inside: $ZIPARCHIVE->registerProgressCallback($RATE, $CALLABLE) + - pattern-inside: $ZMQDEVICE->setIdleCallback($CALLABLE, ...) + - pattern-inside: $ZMQDEVICE->setTimerCallback($CALLABLE, ...) + - pattern-inside: apcu_entry($KEY, $CALLABLE, ...) + - pattern-inside: array_filter($ARRAY, $CALLABLE, ...) + - pattern-inside: array_map($CALLABLE, ...) + - pattern-inside: array_reduce($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk_recursive($ARRAY, $CALLABLE, ...) + - pattern-inside: array_walk($ARRAY, $CALLABLE, ...) + - pattern-inside: call_user_func_array($CALLABLE, ...) + - pattern-inside: call_user_func($CALLABLE, ...) + - pattern-inside: Closure::fromCallable($CALLABLE) + - pattern-inside: createCollation($NAME, $CALLABLE) + - pattern-inside: eio_grp($CALLABLE, ...) + - pattern-inside: eio_nop($PRI, $CALLABLE, ...) + - pattern-inside: eio_sync($PRI, $CALLABLE, ...) + - pattern-inside: EvPrepare::createStopped($CALLABLE, ...) + - pattern-inside: fann_set_callback($ANN, $CALLABLE) + - pattern-inside: fdf_enum_values($FDF_DOCUMENT, $CALLABLE, ...) + - pattern-inside: forward_static_call_array($CALLABLE, ...) + - pattern-inside: forward_static_call($CALLABLE, ...) + - pattern-inside: header_register_callback($CALLABLE) + - pattern-inside: ibase_set_event_handler($CALLABLE, ...) + - pattern-inside: IntlChar::enumCharTypes($CALLABLE) + - pattern-inside: iterator_apply($ITERATOR, $CALLABLE) + - pattern-inside: ldap_set_rebind_proc($LDAP, $CALLABLE) + - pattern-inside: libxml_set_external_entity_loader($CALLABLE, ...) + - pattern-inside: new CallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new EvCheck($CALLABLE, ...) + - pattern-inside: new EventHttpRequest($CALLABLE, ...) + - pattern-inside: new EvFork($CALLABLE, ...) + - pattern-inside: new EvIdle($CALLABLE, ...) + - pattern-inside: new Fiber($CALLABLE) + - pattern-inside: new Memcached($PERSISTENT_ID, $CALLABLE, ...) + - pattern-inside: new RecursiveCallbackFilterIterator($ITERATOR, $CALLABLE) + - pattern-inside: new Zookeeper($HOST, $CALLABLE, ...) + - pattern-inside: ob_start($CALLABLE, ...) + - pattern-inside: oci_register_taf_callback($CONNECTION, $CALLABLE) + - pattern-inside: readline_callback_handler_install($PROMPT, $CALLABLE) + - pattern-inside: readline_completion_function($CALLABLE) + - pattern-inside: register_shutdown_function($CALLABLE, ...) + - pattern-inside: register_tick_function($CALLABLE, ...) + - pattern-inside: rnp_ffi_set_pass_provider($FFI, $CALLABLE) + - pattern-inside: sapi_windows_set_ctrl_handler($CALLABLE, ...) + - pattern-inside: set_error_handler($CALLABLE, ...) + - pattern-inside: set_exception_handler($CALLABLE) + - pattern-inside: setAuthorizer($CALLABLE) + - pattern-inside: spl_autoload_register($CALLABLE, ...) + - pattern-inside: uasort($ARRAY, $CALLABLE) + - pattern-inside: uksort($ARRAY, $CALLABLE) + - pattern-inside: usort($ARRAY, $CALLABLE) + - pattern-inside: xml_set_character_data_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_default_handler($PARSER, $CALLABLE) + - pattern-inside: xml_set_element_handler($PARSER, $CALLABLE, $CALLABLE) + - pattern-inside: xml_set_notation_decl_handler($PARSER, $CALLABLE) + - pattern-inside: Yar_Concurrent_Client::loop($CALLABLE, ...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + severity: WARNING +- id: php.lang.security.injection.tainted-exec.tainted-exec + languages: + - php + message: User input is passed to a function that executes a shell command. This can lead to remote code execution. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 146572 + rule_id: 10UOGG5 + rv_id: 1263286 + url: https://semgrep.dev/playground/r/ExTExyR/php.lang.security.injection.tainted-exec.tainted-exec + version_id: ExTExyR + shortlink: https://sg.run/kxEEz + source: https://semgrep.dev/r/php.lang.security.injection.tainted-exec.tainted-exec + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Command Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: escapeshellcmd(...) + - pattern: escapeshellarg(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: exec(...) + - pattern: system(...) + - pattern: passthru(...) + - patterns: + - pattern: proc_open(...) + - pattern-not: proc_open([...], ...) + - pattern: popen(...) + - pattern: expect_popen(...) + - pattern: shell_exec(...) + - pattern: "`...`\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: file_get_contents('php://input') + severity: WARNING +- id: php.lang.security.injection.tainted-filename.tainted-filename + languages: + - php + message: File name based on user input risks server-side request forgery. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29 + semgrep.dev: + rule: + origin: community + r_id: 16250 + rule_id: 5rUpro + rv_id: 1263287 + url: https://semgrep.dev/playground/r/7ZTE3J1/php.lang.security.injection.tainted-filename.tainted-filename + version_id: 7ZTE3J1 + shortlink: https://sg.run/Ayqp + source: https://semgrep.dev/r/php.lang.security.injection.tainted-filename.tainted-filename + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: basename($PATH, ...) + - pattern-inside: linkinfo($PATH, ...) + - pattern-inside: readlink($PATH, ...) + - pattern-inside: realpath($PATH, ...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: opcache_compile_file($FILENAME, ...) + - pattern-inside: opcache_invalidate($FILENAME, ...) + - pattern-inside: opcache_is_script_cached($FILENAME, ...) + - pattern-inside: runkit7_import($FILENAME, ...) + - pattern-inside: readline_read_history($FILENAME, ...) + - pattern-inside: readline_write_history($FILENAME, ...) + - pattern-inside: rar_open($FILENAME, ...) + - pattern-inside: zip_open($FILENAME, ...) + - pattern-inside: gzfile($FILENAME, ...) + - pattern-inside: gzopen($FILENAME, ...) + - pattern-inside: readgzfile($FILENAME, ...) + - pattern-inside: hash_file($ALGO, $FILENAME, ...) + - pattern-inside: hash_update_file($CONTEXT, $FILENAME, ...) + - pattern-inside: pg_trace($FILENAME, ...) + - pattern-inside: dio_open($FILENAME, ...) + - pattern-inside: finfo_file($FINFO, $FILENAME, ...) + - pattern-inside: mime_content_type($FILENAME, ...) + - pattern-inside: chgrp($FILENAME, ...) + - pattern-inside: chmod($FILENAME, ...) + - pattern-inside: chown($FILENAME, ...) + - pattern-inside: clearstatcache($CLEAR_REALPATH_CACHE, $FILENAME, ...) + - pattern-inside: file_exists($FILENAME, ...) + - pattern-inside: file_get_contents($FILENAME, ...) + - pattern-inside: file_put_contents($FILENAME, ...) + - pattern-inside: file($FILENAME, ...) + - pattern-inside: fileatime($FILENAME, ...) + - pattern-inside: filectime($FILENAME, ...) + - pattern-inside: filegroup($FILENAME, ...) + - pattern-inside: fileinode($FILENAME, ...) + - pattern-inside: filemtime($FILENAME, ...) + - pattern-inside: fileowner($FILENAME, ...) + - pattern-inside: fileperms($FILENAME, ...) + - pattern-inside: filesize($FILENAME, ...) + - pattern-inside: filetype($FILENAME, ...) + - pattern-inside: fnmatch($PATTERN, $FILENAME, ...) + - pattern-inside: fopen($FILENAME, ...) + - pattern-inside: is_dir($FILENAME, ...) + - pattern-inside: is_executable($FILENAME, ...) + - pattern-inside: is_file($FILENAME, ...) + - pattern-inside: is_link($FILENAME, ...) + - pattern-inside: is_readable($FILENAME, ...) + - pattern-inside: is_uploaded_file($FILENAME, ...) + - pattern-inside: is_writable($FILENAME, ...) + - pattern-inside: lchgrp($FILENAME, ...) + - pattern-inside: lchown($FILENAME, ...) + - pattern-inside: lstat($FILENAME, ...) + - pattern-inside: parse_ini_file($FILENAME, ...) + - pattern-inside: readfile($FILENAME, ...) + - pattern-inside: stat($FILENAME, ...) + - pattern-inside: touch($FILENAME, ...) + - pattern-inside: unlink($FILENAME, ...) + - pattern-inside: xattr_get($FILENAME, ...) + - pattern-inside: xattr_list($FILENAME, ...) + - pattern-inside: xattr_remove($FILENAME, ...) + - pattern-inside: xattr_set($FILENAME, ...) + - pattern-inside: xattr_supported($FILENAME, ...) + - pattern-inside: enchant_broker_request_pwl_dict($BROKER, $FILENAME, ...) + - pattern-inside: pspell_config_personal($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_config_repl($CONFIG, $FILENAME, ...) + - pattern-inside: pspell_new_personal($FILENAME, ...) + - pattern-inside: exif_imagetype($FILENAME, ...) + - pattern-inside: getimagesize($FILENAME, ...) + - pattern-inside: image2wbmp($IMAGE, $FILENAME, ...) + - pattern-inside: imagecreatefromavif($FILENAME, ...) + - pattern-inside: imagecreatefrombmp($FILENAME, ...) + - pattern-inside: imagecreatefromgd2($FILENAME, ...) + - pattern-inside: imagecreatefromgd2part($FILENAME, ...) + - pattern-inside: imagecreatefromgd($FILENAME, ...) + - pattern-inside: imagecreatefromgif($FILENAME, ...) + - pattern-inside: imagecreatefromjpeg($FILENAME, ...) + - pattern-inside: imagecreatefrompng($FILENAME, ...) + - pattern-inside: imagecreatefromtga($FILENAME, ...) + - pattern-inside: imagecreatefromwbmp($FILENAME, ...) + - pattern-inside: imagecreatefromwebp($FILENAME, ...) + - pattern-inside: imagecreatefromxbm($FILENAME, ...) + - pattern-inside: imagecreatefromxpm($FILENAME, ...) + - pattern-inside: imageloadfont($FILENAME, ...) + - pattern-inside: imagexbm($IMAGE, $FILENAME, ...) + - pattern-inside: iptcembed($IPTC_DATA, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_part_file($MIMEMAIL, $FILENAME, ...) + - pattern-inside: mailparse_msg_extract_whole_part_file($MIMEMAIL, $FILENAME, ...) + - pattern-inside: mailparse_msg_parse_file($FILENAME, ...) + - pattern-inside: fdf_add_template($FDF_DOCUMENT, $NEWPAGE, $FILENAME, ...) + - pattern-inside: fdf_get_ap($FDF_DOCUMENT, $FIELD, $FACE, $FILENAME, ...) + - pattern-inside: fdf_open($FILENAME, ...) + - pattern-inside: fdf_save($FDF_DOCUMENT, $FILENAME, ...) + - pattern-inside: fdf_set_ap($FDF_DOCUMENT, $FIELD_NAME, $FACE, $FILENAME, ...) + - pattern-inside: ps_add_launchlink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) + - pattern-inside: ps_add_pdflink($PSDOC, $LLX, $LLY, $URX, $URY, $FILENAME, ...) + - pattern-inside: ps_open_file($PSDOC, $FILENAME, ...) + - pattern-inside: ps_open_image_file($PSDOC, $TYPE, $FILENAME, ...) + - pattern-inside: posix_access($FILENAME, ...) + - pattern-inside: posix_mkfifo($FILENAME, ...) + - pattern-inside: posix_mknod($FILENAME, ...) + - pattern-inside: ftok($FILENAME, ...) + - pattern-inside: fann_cascadetrain_on_file($ANN, $FILENAME, ...) + - pattern-inside: fann_read_train_from_file($FILENAME, ...) + - pattern-inside: fann_train_on_file($ANN, $FILENAME, ...) + - pattern-inside: highlight_file($FILENAME, ...) + - pattern-inside: php_strip_whitespace($FILENAME, ...) + - pattern-inside: stream_resolve_include_path($FILENAME, ...) + - pattern-inside: swoole_async_read($FILENAME, ...) + - pattern-inside: swoole_async_readfile($FILENAME, ...) + - pattern-inside: swoole_async_write($FILENAME, ...) + - pattern-inside: swoole_async_writefile($FILENAME, ...) + - pattern-inside: swoole_load_module($FILENAME, ...) + - pattern-inside: tidy_parse_file($FILENAME, ...) + - pattern-inside: tidy_repair_file($FILENAME, ...) + - pattern-inside: get_meta_tags($FILENAME, ...) + - pattern-inside: yaml_emit_file($FILENAME, ...) + - pattern-inside: yaml_parse_file($FILENAME, ...) + - pattern-inside: curl_file_create($FILENAME, ...) + - pattern-inside: ftp_chmod($FTP, $PERMISSIONS, $FILENAME, ...) + - pattern-inside: ftp_delete($FTP, $FILENAME, ...) + - pattern-inside: ftp_mdtm($FTP, $FILENAME, ...) + - pattern-inside: ftp_size($FTP, $FILENAME, ...) + - pattern-inside: rrd_create($FILENAME, ...) + - pattern-inside: rrd_fetch($FILENAME, ...) + - pattern-inside: rrd_graph($FILENAME, ...) + - pattern-inside: rrd_info($FILENAME, ...) + - pattern-inside: rrd_last($FILENAME, ...) + - pattern-inside: rrd_lastupdate($FILENAME, ...) + - pattern-inside: rrd_tune($FILENAME, ...) + - pattern-inside: rrd_update($FILENAME, ...) + - pattern-inside: snmp_read_mib($FILENAME, ...) + - pattern-inside: ssh2_sftp_chmod($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_realpath($SFTP, $FILENAME, ...) + - pattern-inside: ssh2_sftp_unlink($SFTP, $FILENAME, ...) + - pattern-inside: apache_lookup_uri($FILENAME, ...) + - pattern-inside: md5_file($FILENAME, ...) + - pattern-inside: sha1_file($FILENAME, ...) + - pattern-inside: simplexml_load_file($FILENAME, ...) + - pattern: $FILENAME + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + severity: WARNING +- id: php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + languages: + - php + message: <- A new object is created where the class name is based on user input. This could lead to remote code + execution, as it allows to instantiate any class in the application. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 16438 + rule_id: v8U4DA + rv_id: 1263288 + url: + https://semgrep.dev/playground/r/LjTkgLy/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + version_id: LjTkgLy + shortlink: https://sg.run/7ndw + source: https://semgrep.dev/r/php.lang.security.injection.tainted-object-instantiation.tainted-object-instantiation + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Improper Authorization + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: new $SINK(...) + - pattern: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + severity: WARNING +- id: php.lang.security.injection.tainted-session.tainted-session + languages: + - php + message: Session key based on user input risks session poisoning. The user can determine the key used for the session, + and thus write any session variable. Session variables are typically trusted to be set only by the application, and + manipulating the session can result in access control issues. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-284: Improper Access Control' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://en.wikipedia.org/wiki/Session_poisoning + semgrep.dev: + rule: + origin: community + r_id: 73470 + rule_id: 4bUdoP + rv_id: 1263289 + url: https://semgrep.dev/playground/r/8KT5rPE/php.lang.security.injection.tainted-session.tainted-session + version_id: 8KT5rPE + shortlink: https://sg.run/bxNp + source: https://semgrep.dev/r/php.lang.security.injection.tainted-session.tainted-session + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Improper Authorization + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern: $A . $B + - pattern: bin2hex(...) + - pattern: crc32(...) + - pattern: crypt(...) + - pattern: filter_input(...) + - pattern: filter_var(...) + - pattern: hash(...) + - pattern: md5(...) + - pattern: preg_filter(...) + - pattern: preg_grep(...) + - pattern: preg_match_all(...) + - pattern: sha1(...) + - pattern: sprintf(...) + - pattern: str_contains(...) + - pattern: str_ends_with(...) + - pattern: str_starts_with(...) + - pattern: strcasecmp(...) + - pattern: strchr(...) + - pattern: stripos(...) + - pattern: stristr(...) + - pattern: strnatcasecmp(...) + - pattern: strnatcmp(...) + - pattern: strncmp(...) + - pattern: strpbrk(...) + - pattern: strpos(...) + - pattern: strripos(...) + - pattern: strrpos(...) + - pattern: strspn(...) + - pattern: strstr(...) + - pattern: strtok(...) + - pattern: substr_compare(...) + - pattern: substr_count(...) + - pattern: vsprintf(...) + pattern-sinks: + - patterns: + - pattern-inside: $_SESSION[$KEY] = $VAL; + - pattern: $KEY + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + severity: WARNING +- id: php.lang.security.injection.tainted-sql-string.tainted-sql-string + languages: + - php + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`$mysqli->prepare("INSERT INTO test(id, label) VALUES (?, ?)");`) or a safe library. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 14757 + rule_id: qNUXdL + rv_id: 1263290 + url: https://semgrep.dev/playground/r/gETB7vY/php.lang.security.injection.tainted-sql-string.tainted-sql-string + version_id: gETB7vY + shortlink: https://sg.run/lZYG + source: https://semgrep.dev/r/php.lang.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - php + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: mysqli_real_escape_string(...) + - pattern: real_escape_string(...) + - pattern: $MYSQLI->real_escape_string(...) + pattern-sinks: + - pattern-either: + - patterns: + - pattern: "sprintf($SQLSTR, ...)\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: "\"...$EXPR...\"\n" + - metavariable-regex: + metavariable: $EXPR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + - patterns: + - pattern: "\"$SQLSTR\".$EXPR\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?is).*\b(select|delete|insert|create|update|alter|drop)\b.* + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + severity: ERROR +- id: php.lang.security.injection.tainted-url-host.tainted-url-host + languages: + - php + message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send + data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with + this request. They could also probe internal servers or other resources that the server running this code can + access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an + allowlist for approved hosts, or hardcode the correct host. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 14758 + rule_id: lBU8K1 + rv_id: 1263291 + url: https://semgrep.dev/playground/r/QkTGqRd/php.lang.security.injection.tainted-url-host.tainted-url-host + version_id: QkTGqRd + shortlink: https://sg.run/Y8no + source: https://semgrep.dev/r/php.lang.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - pattern-either: + - patterns: + - pattern: "sprintf($URLSTR, ...)\n" + - metavariable-pattern: + language: generic + metavariable: $URLSTR + pattern: $SCHEME://%s + - patterns: + - pattern: "\"...{$EXPR}...\"\n" + - pattern-regex: ".*://\\{.*\n" + - patterns: + - pattern: "\"...$EXPR...\"\n" + - pattern-regex: ".*://\\$.*\n" + - patterns: + - pattern: "\"...\".$EXPR\n" + - pattern-regex: ".*://[\"'].*\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + severity: WARNING +- id: php.lang.security.md5-used-as-password.md5-used-as-password + languages: + - php + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as bcrypt. You can + use `password_hash($PASSWORD, PASSWORD_BCRYPT, $OPTIONS);`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://www.php.net/password_hash + semgrep.dev: + rule: + origin: community + r_id: 14759 + rule_id: YGUD1O + rv_id: 1263294 + url: https://semgrep.dev/playground/r/PkTR37j/php.lang.security.md5-used-as-password.md5-used-as-password + version_id: PkTR37j + shortlink: https://sg.run/66YL + source: https://semgrep.dev/r/php.lang.security.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: md5(...) + - pattern: hash('md5', ...) + severity: WARNING +- id: php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + languages: + - php + message: Static IV used with AES in CBC mode. Static IVs enable chosen-plaintext attacks against encrypted data. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-329: Generation of Predictable IV with CBC Mode' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://csrc.nist.gov/publications/detail/sp/800-38a/final + semgrep.dev: + rule: + origin: community + r_id: 19039 + rule_id: DbUGbE + rv_id: 1263295 + url: https://semgrep.dev/playground/r/JdTzxOD/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + version_id: JdTzxOD + shortlink: https://sg.run/LgWJ + source: https://semgrep.dev/r/php.lang.security.openssl-cbc-static-iv.openssl-cbc-static-iv + subcategory: + - vuln + technology: + - php + - openssl + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: openssl_encrypt($D, $M, $K, $FLAGS, "...",...); + - pattern: openssl_decrypt($D, $M, $K, $FLAGS, "...",...); + - metavariable-comparison: + comparison: re.match(".*-CBC",$M) + metavariable: $M + severity: ERROR +- id: php.lang.security.phpinfo-use.phpinfo-use + languages: + - php + message: The 'phpinfo' function may reveal sensitive information about your environment. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.php.net/manual/en/function.phpinfo + - https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/PhpinfosSniff.php + semgrep.dev: + rule: + origin: community + r_id: 9397 + rule_id: ReUglY + rv_id: 1263298 + url: https://semgrep.dev/playground/r/RGT0LN0/php.lang.security.phpinfo-use.phpinfo-use + version_id: RGT0LN0 + shortlink: https://sg.run/W82E + source: https://semgrep.dev/r/php.lang.security.phpinfo-use.phpinfo-use + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Mishandled Sensitive Information + pattern: phpinfo(...); + severity: ERROR +- id: php.lang.security.redirect-to-request-uri.redirect-to-request-uri + languages: + - php + message: Redirecting to the current request URL may redirect to another domain, if the current path starts with two + slashes. E.g. in https://www.example.com//attacker.com, the value of REQUEST_URI is //attacker.com, and redirecting + to it will redirect to that domain. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.php.net/manual/en/reserved.variables.server.php + - https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html + semgrep.dev: + rule: + origin: community + r_id: 35493 + rule_id: 3qUb4n + rv_id: 1263299 + url: https://semgrep.dev/playground/r/A8Tgdvq/php.lang.security.redirect-to-request-uri.redirect-to-request-uri + version_id: A8Tgdvq + shortlink: https://sg.run/RWl2 + source: https://semgrep.dev/r/php.lang.security.redirect-to-request-uri.redirect-to-request-uri + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Open Redirect + patterns: + - pattern-either: + - pattern: "header('$LOCATION' . $_SERVER['REQUEST_URI']);\n" + - pattern: "header('$LOCATION' . $_SERVER['REQUEST_URI'] . $MORE);\n" + - metavariable-regex: + metavariable: $LOCATION + regex: ^(?i)location:\s*$ + severity: WARNING +- id: php.lang.security.tainted-exec.tainted-exec + languages: + - php + message: Executing non-constant commands. This can lead to command injection. You should use `escapeshellarg()` when + using command. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.stackhawk.com/blog/php-command-injection/ + - https://brightsec.com/blog/code-injection-php/ + - https://www.acunetix.com/websitesecurity/php-security-2/ + semgrep.dev: + rule: + origin: community + r_id: 73146 + rule_id: 9AUw06 + rv_id: 1263300 + url: https://semgrep.dev/playground/r/BjTkZ4y/php.lang.security.tainted-exec.tainted-exec + version_id: BjTkZ4y + shortlink: https://sg.run/JAkP + source: https://semgrep.dev/r/php.lang.security.tainted-exec.tainted-exec + subcategory: + - vuln + technology: + - php + vulnerability_class: + - Code Injection + mode: taint + pattern-sanitizers: + - pattern: escapeshellarg(...) + pattern-sinks: + - pattern: exec(...) + - pattern: system(...) + - pattern: popen(...) + - pattern: passthru(...) + - pattern: shell_exec(...) + - pattern: pcntl_exec(...) + - pattern: proc_open(...) + pattern-sources: + - pattern: $_REQUEST + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + severity: ERROR +- id: php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + languages: + - php + message: HTTP method [$METHOD] to Laravel route $ROUTE_NAME is vulnerable to SQL injection via string concatenation or + unsafe interpolation. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Laravel_Cheat_Sheet.md + semgrep.dev: + rule: + origin: community + r_id: 21674 + rule_id: zdUln0 + rv_id: 1263305 + url: + https://semgrep.dev/playground/r/qkTR7A9/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + version_id: qkTR7A9 + shortlink: https://sg.run/x94g + source: https://semgrep.dev/r/php.laravel.security.laravel-api-route-sql-injection.laravel-api-route-sql-injection + subcategory: + - vuln + technology: + - php + - laravel + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "DB::raw(\"...\",[...])\n" + pattern-sinks: + - patterns: + - pattern: "DB::raw(...)\n" + pattern-sources: + - patterns: + - focus-metavariable: $ARG + - pattern-inside: "Route::$METHOD($ROUTE_NAME, function(...,$ARG,...){...})\n" + severity: WARNING +- id: php.laravel.security.laravel-sql-injection.laravel-sql-injection + languages: + - php + message: Detected a SQL query based on user input. This could lead to SQL injection, which could potentially result in + sensitive data being exfiltrated by attackers. Instead, use parameterized queries and prepared statements. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://laravel.com/docs/8.x/queries + semgrep.dev: + rule: + origin: community + r_id: 16830 + rule_id: j2UQdp + rv_id: 1263313 + url: https://semgrep.dev/playground/r/BjTkZ45/php.laravel.security.laravel-sql-injection.laravel-sql-injection + version_id: BjTkZ45 + shortlink: https://sg.run/x40p + source: https://semgrep.dev/r/php.laravel.security.laravel-sql-injection.laravel-sql-injection + subcategory: + - vuln + technology: + - laravel + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $SQL + - pattern-either: + - pattern-inside: DB::table(...)->whereRaw($SQL, ...) + - pattern-inside: DB::table(...)->orWhereRaw($SQL, ...) + - pattern-inside: DB::table(...)->groupByRaw($SQL, ...) + - pattern-inside: DB::table(...)->havingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orHavingRaw($SQL, ...) + - pattern-inside: DB::table(...)->orderByRaw($SQL, ...) + - patterns: + - pattern: $EXPRESSION + - pattern-either: + - pattern-inside: DB::table(...)->selectRaw($EXPRESSION, ...) + - pattern-inside: DB::table(...)->fromRaw($EXPRESSION, ...) + - patterns: + - pattern: $COLUMNS + - pattern-either: + - pattern-inside: DB::table(...)->whereNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereNull($COLUMN) + - pattern-inside: DB::table(...)->whereNotNull($COLUMNS, ...) + - pattern-inside: DB::table(...)->whereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->orWhereRowValues($COLUMNS, ...) + - pattern-inside: DB::table(...)->find($ID, $COLUMNS) + - pattern-inside: DB::table(...)->paginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->simplePaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->cursorPaginate($PERPAGE, $COLUMNS, ...) + - pattern-inside: DB::table(...)->getCountForPagination($COLUMNS) + - pattern-inside: DB::table(...)->aggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->numericAggregate($FUNCTION, $COLUMNS) + - pattern-inside: DB::table(...)->insertUsing($COLUMNS, ...) + - pattern-inside: DB::table(...)->select($COLUMNS) + - pattern-inside: DB::table(...)->get($COLUMNS) + - pattern-inside: DB::table(...)->count($COLUMNS) + - patterns: + - pattern: $COLUMN + - pattern-either: + - pattern-inside: DB::table(...)->whereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotIn($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereIntegerNotInRaw($COLUMN, ...) + - pattern-inside: DB::table(...)->whereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->whereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotBetweenColumns($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereNotNull($COLUMN) + - pattern-inside: DB::table(...)->whereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDate($COLUMN, ...) + - pattern-inside: DB::table(...)->whereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereTime($COLUMN, ...) + - pattern-inside: DB::table(...)->whereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereDay($COLUMN, ...) + - pattern-inside: DB::table(...)->whereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereMonth($COLUMN, ...) + - pattern-inside: DB::table(...)->whereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereYear($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonContains($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonDoesntContain($COLUMN, ...) + - pattern-inside: DB::table(...)->whereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhereJsonLength($COLUMN, ...) + - pattern-inside: DB::table(...)->having($COLUMN, ...) + - pattern-inside: DB::table(...)->orHaving($COLUMN, ...) + - pattern-inside: DB::table(...)->havingBetween($COLUMN, ...) + - pattern-inside: DB::table(...)->orderBy($COLUMN, ...) + - pattern-inside: DB::table(...)->orderByDesc($COLUMN) + - pattern-inside: DB::table(...)->latest($COLUMN) + - pattern-inside: DB::table(...)->oldest($COLUMN) + - pattern-inside: DB::table(...)->forPageBeforeId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->forPageAfterId($PERPAGE, $LASTID, $COLUMN) + - pattern-inside: DB::table(...)->value($COLUMN) + - pattern-inside: DB::table(...)->pluck($COLUMN, ...) + - pattern-inside: DB::table(...)->implode($COLUMN, ...) + - pattern-inside: DB::table(...)->min($COLUMN) + - pattern-inside: DB::table(...)->max($COLUMN) + - pattern-inside: DB::table(...)->sum($COLUMN) + - pattern-inside: DB::table(...)->avg($COLUMN) + - pattern-inside: DB::table(...)->average($COLUMN) + - pattern-inside: DB::table(...)->increment($COLUMN, ...) + - pattern-inside: DB::table(...)->decrement($COLUMN, ...) + - pattern-inside: DB::table(...)->where($COLUMN, ...) + - pattern-inside: DB::table(...)->orWhere($COLUMN, ...) + - pattern-inside: DB::table(...)->addSelect($COLUMN) + - patterns: + - pattern: $QUERY + - pattern-inside: DB::unprepared($QUERY) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET + - pattern: $_POST + - pattern: $_COOKIE + - pattern: $_REQUEST + - pattern: $_SERVER + severity: WARNING +- id: php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + languages: + - php + message: Found a request argument passed to an `ignore()` definition in a Rule constraint. This can lead to SQL + injection. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://laravel.com/docs/9.x/validation#rule-unique + semgrep.dev: + rule: + origin: community + r_id: 21677 + rule_id: X5ULgE + rv_id: 1263314 + url: + https://semgrep.dev/playground/r/DkTRbBl/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + version_id: DkTRbBl + shortlink: https://sg.run/vkeb + source: https://semgrep.dev/r/php.laravel.security.laravel-unsafe-validator.laravel-unsafe-validator + subcategory: + - vuln + technology: + - php + - laravel + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: "Illuminate\\Validation\\Rule::unique(...)->ignore(...,$IGNORE,...)\n" + - focus-metavariable: $IGNORE + pattern-sources: + - patterns: + - pattern: "public function $F(...,Request $R,...){...}\n" + - focus-metavariable: $R + - patterns: + - pattern-either: + - pattern: "$this->$PROPERTY\n" + - pattern: "$this->$PROPERTY->$GET\n" + - metavariable-pattern: + metavariable: $PROPERTY + patterns: + - pattern-either: + - pattern: query + - pattern: request + - pattern: headers + - pattern: cookies + - pattern: cookie + - pattern: files + - pattern: file + - pattern: allFiles + - pattern: input + - pattern: all + - pattern: post + - pattern: json + - pattern-either: + - pattern-inside: "class $CL extends Illuminate\\Http\\Request {...}\n" + - pattern-inside: "class $CL extends Illuminate\\Foundation\\Http\\FormRequest {...}\n" + severity: ERROR +- id: php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + languages: + - php + message: Detected usage of vulnerable functions with user input, which could lead to SSRF vulnerabilities. + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-918: Server-Side Request Forgery (SSRF)' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A10:2021 - Server-Side Request Forgery (SSRF) + references: + - https://developer.wordpress.org/reference/functions/wp_safe_remote_get/ + - https://developer.wordpress.org/reference/functions/wp_remote_get/ + - https://patchstack.com/articles/exploring-the-unpatched-wordpress-ssrf/ + semgrep.dev: + rule: + origin: community + r_id: 191611 + rule_id: 6JUZyKX + rv_id: 1039233 + url: https://semgrep.dev/playground/r/JdTp6rq/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + version_id: JdTp6rq + shortlink: https://sg.run/K3y06 + source: https://semgrep.dev/r/php.wordpress-plugins.security.audit.wp-ssrf-audit.wp-ssrf-audit + subcategory: + - audit + technology: + - Wordpress Plugins + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + paths: + include: + - '**/wp-content/plugins/**/*.php' + pattern-sinks: + - patterns: + - focus-metavariable: $URL + - pattern-either: + - pattern: wp_remote_get($URL, ...) + - pattern: wp_safe_remote_get($URL, ...) + - pattern: wp_safe_remote_request($URL, ...) + - pattern: wp_safe_remote_head($URL, ...) + - pattern: wp_oembed_get($URL, ...) + - pattern: vip_safe_wp_remote_get($URL, ...) + - pattern: wp_safe_remote_post($URL, ...) + pattern-sources: + - patterns: + - pattern-either: + - pattern: $_GET[...] + - pattern: $_POST[...] + - pattern: $_REQUEST[...] + - pattern: get_option(...) + - pattern: get_user_meta(...) + - pattern: get_query_var(...) + severity: WARNING +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + languages: + - java + message: Detected an HTTP request sent via HttpGet. This could lead to sensitive information being sent over an + insecure channel. Instead, it is recommended to send requests over HTTPS. + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A03:2017 - Sensitive Data Exposure + references: + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URLConnection.html + - https://docs.oracle.com/en/java/javase/11/docs/api/java.base/java/net/URL.html#openConnection() + semgrep.dev: + rule: + origin: community + r_id: 48942 + rule_id: 6JUOJ2 + rv_id: 946061 + url: + https://semgrep.dev/playground/r/WrTEo9G/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + version_id: WrTEo9G + shortlink: https://sg.run/QE2q + source: + https://semgrep.dev/r/problem-based-packs.insecure-transport.java-stdlib.httpget-http-request.httpget-http-request + subcategory: + - vuln + technology: + - java + vulnerability: Insecure Transport + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: "\"=~/[Hh][Tt][Tt][Pp]://.*/\"\n" + - pattern-inside: "$R = new HttpGet(\"=~/[Hh][Tt][Tt][Pp]://.*/\");\n...\n$CLIENT. ... .execute($R, ...);\n" + severity: WARNING +- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + languages: + - python + message: Detected 'create_subprocess_exec' function with argument tainted by `event` object. If this data can be + controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it + is not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18260 + rule_id: EwUrX8 + rv_id: 1263331 + url: + https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + version_id: rxTAKgo + shortlink: https://sg.run/oyv0 + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], + ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + languages: + - python + message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted by `event` object. If this data + can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to + ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18261 + rule_id: 7KUxXg + rv_id: 1263332 + url: + https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + version_id: bZT53Ww + shortlink: https://sg.run/z14d + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + languages: + - python + message: Detected asyncio subprocess function with argument tainted by `event` object. If this data can be controlled + by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not + controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18262 + rule_id: L1UEl7 + rv_id: 1263333 + url: + https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + version_id: NdTzyWA + shortlink: https://sg.run/p9vZ + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern: asyncio.create_subprocess_shell($CMD, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + languages: + - python + message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach + this function call because it allows a malicious actor to execute commands. Ensure no external data reaches here. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18263 + rule_id: 8GUGBq + rv_id: 1263334 + url: + https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + version_id: kbTzGv8 + shortlink: https://sg.run/2AjL + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - patterns: + - pattern: os.$METHOD($MODE, $CMD, ...) + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + languages: + - python + message: Detected subprocess function with argument tainted by an `event` object. If this data can be controlled by a + malicious actor, it may be an instance of command injection. The default option for `shell` is False, and this is + secure by default. Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` means + you have to split the command string into an array of strings for the command and its arguments. You may consider + using 'shlex.split()' for this purpose. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18264 + rule_id: gxUyn1 + rv_id: 1263335 + url: + https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + version_id: w8TRogj + shortlink: https://sg.run/XZ7B + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sanitizers: + - pattern: shlex.split(...) + - pattern: pipes.quote(...) + - pattern: shlex.quote(...) + pattern-sinks: + - patterns: + - pattern: subprocess.$FUNC(..., shell=True, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call + languages: + - python + message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach + this function call because it allows a malicious actor to execute commands. Use the 'subprocess' module instead, + which is easier to use without accidentally exposing a command injection vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18265 + rule_id: QrUkg6 + rv_id: 1263336 + url: + https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + version_id: xyTjzbG + shortlink: https://sg.run/jDvN + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: os.system($CMD,...) + - pattern: os.popen($CMD,...) + - pattern: os.popen2($CMD,...) + - pattern: os.popen3($CMD,...) + - pattern: os.popen4($CMD,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + languages: + - python + message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This could lead to NoSQL injection if the + variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from + `$EVENT` directly to DynamoDB client. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + references: + - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac + semgrep.dev: + rule: + origin: community + r_id: 21321 + rule_id: KxUJ2B + rv_id: 946088 + url: + https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + version_id: 9lTy1rQ + shortlink: https://sg.run/jjrl + source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + subcategory: + - vuln + technology: + - python + - boto3 + - aws-lambda + - dynamodb + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "{...}\n" + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) + - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) + - pattern-either: + - patterns: + - pattern-inside: "$TABLE = $DB.Table(...)\n...\n" + - pattern-inside: "$DB = boto3.resource('dynamodb', ...)\n...\n" + - pattern-inside: "$TABLE = boto3.client('dynamodb', ...)\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', ('active'))`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html + semgrep.dev: + rule: + origin: community + r_id: 18266 + rule_id: 3qU3eE + rv_id: 1263337 + url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli + version_id: O9TpxLJ + shortlink: https://sg.run/1RjG + source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - mysql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern-either: + - pattern-inside: "import mysql\n...\n" + - pattern-inside: "import mysql.cursors\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.psycopg.org/docs/cursor.html#cursor.execute + - https://www.psycopg.org/docs/cursor.html#cursor.executemany + - https://www.psycopg.org/docs/cursor.html#cursor.mogrify + semgrep.dev: + rule: + origin: community + r_id: 18267 + rule_id: 4bUQG1 + rv_id: 1263338 + url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + version_id: e1TyjPZ + shortlink: https://sg.run/9L8r + source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + subcategory: + - vuln + technology: + - aws-lambda + - psycopg + - psycopg2 + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern: $CURSOR.mogrify($QUERY,...) + - pattern-inside: "import psycopg2\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pypi.org/project/pymssql/ + semgrep.dev: + rule: + origin: community + r_id: 18268 + rule_id: PeUxO0 + rv_id: 1263339 + url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + version_id: vdT06bG + shortlink: https://sg.run/yXvP + source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - pymssql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: "import pymssql\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', ('active'))`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pypi.org/project/PyMySQL/#id4 + semgrep.dev: + rule: + origin: community + r_id: 18269 + rule_id: JDUlel + rv_id: 1263340 + url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + version_id: d6TyxNA + shortlink: https://sg.run/reve + source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - pymysql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-either: + - pattern-inside: "import pymysql\n...\n" + - pattern-inside: "import pymysql.cursors\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = ?', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute + semgrep.dev: + rule: + origin: community + r_id: 18270 + rule_id: 5rUy3N + rv_id: 1263341 + url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + version_id: ZRTKARp + shortlink: https://sg.run/b48W + source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + subcategory: + - vuln + technology: + - aws-lambda + - sqlalchemy + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: "import sqlalchemy\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec + languages: + - python + message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate dynamic content. If this content + can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not + definable by external sources. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18271 + rule_id: GdUDJP + rv_id: 1263342 + url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + version_id: nWT2LD2 + shortlink: https://sg.run/Ng7y + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval($CODE, ...) + - pattern: exec($CODE, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-html-response.tainted-html-response + languages: + - python + message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of + rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could + let attackers steal sensitive user data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18272 + rule_id: ReUKrk + rv_id: 1263343 + url: + https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response + version_id: ExTEx5o + shortlink: https://sg.run/k9vP + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern: $BODY + - pattern-inside: "{..., \"headers\": {..., \"Content-Type\": \"text/html\", ...}, \"body\": $BODY, ... }\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18484 + rule_id: JDUlwy + rv_id: 1263344 + url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string + version_id: 7ZTE36K + shortlink: https://sg.run/8zNy + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - pattern-not-inside: "print(...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + languages: + - python + message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the + serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON + or a similar text-based serialization format. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ + semgrep.dev: + rule: + origin: community + r_id: 21602 + rule_id: JDUDQg + rv_id: 1263345 + url: + https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + version_id: LjTkgd9 + shortlink: https://sg.run/JbjW + source: + https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: pickle.load($SINK,...) + - pattern: pickle.loads($SINK,...) + - pattern: _pickle.load($SINK,...) + - pattern: _pickle.loads($SINK,...) + - pattern: cPickle.load($SINK,...) + - pattern: cPickle.loads($SINK,...) + - pattern: dill.load($SINK,...) + - pattern: dill.loads($SINK,...) + - pattern: shelve.open($SINK,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18273 + rule_id: AbU3LX + rv_id: 1263346 + url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: 8KT5ron + shortlink: https://sg.run/wXvA + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\" % ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - pattern: "f\"$SQLSTR{...}...\"\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= + - pattern-not-inside: "print(...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.boto3.security.hardcoded-token.hardcoded-token + languages: + - python + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://bento.dev/checks/boto3/hardcoded-access-token/ + - https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/ + semgrep.dev: + rule: + origin: community + r_id: 9439 + rule_id: 5rUOwK + rv_id: 1263347 + url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token + version_id: gETB78n + shortlink: https://sg.run/LwQ6 + source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token + subcategory: + - vuln + technology: + - boto3 + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $W(...,$TOKEN="$VALUE",...) + - pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...) + - metavariable-regex: + metavariable: $TOKEN + regex: (aws_session_token|aws_access_key_id|aws_secret_access_key) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^AKI + - pattern-regex: ^[A-Za-z0-9/+=]+$ + - metavariable-analysis: + analyzer: entropy + metavariable: $VALUE + pattern-sources: + - pattern: "\"...\"\n" + severity: WARNING +- id: python.cryptography.security.empty-aes-key.empty-aes-key + languages: + - python + message: Potential empty AES encryption key. Using an empty key in AES encryption can result in weak encryption and + may allow attackers to easily decrypt sensitive data. Ensure that a strong, non-empty key is used for AES + encryption. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-310: Cryptographic Issues' + functional-categories: + - crypto::search::key-length::pycrypto + - crypto::search::key-length::pycryptodome + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A6:2017 misconfiguration + references: + - https://cwe.mitre.org/data/definitions/327.html + - https://cwe.mitre.org/data/definitions/310.html + semgrep.dev: + rule: + origin: community + r_id: 44817 + rule_id: OrUADK + rv_id: 946105 + url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key + version_id: 8KTKjRg + shortlink: https://sg.run/zQ9G + source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key + subcategory: + - vuln + technology: + - python + - pycrypto + - pycryptodome + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: AES.new("",...) + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + languages: + - python + message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial stream output. Its use is + strongly discouraged. ARC4 does not use mode constructions. Use a strong symmetric cipher such as EAS instead. With + the `cryptography` package it is recommended to use the `Fernet` which is a secure implementation of AES in CBC mode + with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES + algorithm instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + semgrep.dev: + rule: + origin: community + r_id: 33630 + rule_id: KxU8gK + rv_id: 1263348 + url: + https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + version_id: QkTGq3Q + shortlink: https://sg.run/xoZL + source: + https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) + - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) + - metavariable-regex: + metavariable: $ARC4 + regex: ^(ARC4)$ + - focus-metavariable: $ARC4 + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + languages: + - python + message: Blowfish is a block cipher developed by Bruce Schneier. It is known to be susceptible to attacks when using + weak keys. The author has recommended that users of Blowfish move to newer algorithms such as AES. With the + `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a + 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm + instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + - https://tools.ietf.org/html/rfc5469 + semgrep.dev: + rule: + origin: community + r_id: 33631 + rule_id: qNULvO + rv_id: 1263349 + url: + https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + version_id: 3ZT4XK7 + shortlink: https://sg.run/OdzL + source: + https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) + - metavariable-regex: + metavariable: $BLOWFISH + regex: ^(Blowfish)$ + - focus-metavariable: $BLOWFISH + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + languages: + - python + message: IDEA (International Data Encryption Algorithm) is a block cipher created in 1991. It is an optional + component of the OpenPGP standard. This cipher is susceptible to attacks when using weak keys. It is recommended + that you do not use this cipher for new applications. Use a strong symmetric cipher such as EAS instead. With the + `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a + 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm + instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc5469 + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA + semgrep.dev: + rule: + origin: community + r_id: 9443 + rule_id: BYUNPg + rv_id: 1263350 + url: + https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + version_id: 44TEjNJ + shortlink: https://sg.run/3xyK + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY) + - metavariable-regex: + metavariable: $IDEA + regex: ^(IDEA)$ + - focus-metavariable: $IDEA + severity: WARNING +- fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV) + id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + languages: + - python + message: ECB (Electronic Code Book) is the simplest mode of operation for block ciphers. Each block of data is + encrypted in the same way. This means identical plaintext blocks will always result in identical ciphertext blocks, + which can leave significant patterns in the output. Use a different, cryptographically strong mode instead, such as + GCM. + metadata: + bandit-code: B305 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::mode::cryptography + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes + - https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption + semgrep.dev: + rule: + origin: community + r_id: 9444 + rule_id: DbUp5g + rv_id: 1263351 + url: + https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + version_id: PkTR3w7 + shortlink: https://sg.run/4xr5 + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101 + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV) + severity: WARNING +- fix: SHA256 + id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33632 + rule_id: lBUopp + rv_id: 1263352 + url: + https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + version_id: JdTzxww + shortlink: https://sg.run/eY88 + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$MD5() + - metavariable-regex: + metavariable: $MD5 + regex: ^(MD5)$ + - focus-metavariable: $MD5 + severity: WARNING +- fix: "SHA256\n" + id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9446 + rule_id: 0oU5dN + rv_id: 1263353 + url: + https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + version_id: 5PTo1l0 + shortlink: https://sg.run/J9Qy + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$SHA(...) + - metavariable-pattern: + metavariable: $SHA + pattern: "SHA1\n" + - focus-metavariable: $SHA + severity: WARNING +- fix: "2048\n" + id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + languages: + - python + message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + semgrep.dev: + rule: + origin: community + r_id: 9447 + rule_id: KxUb0x + rv_id: 1263354 + url: + https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + version_id: GxTkeOK + shortlink: https://sg.run/5Qb0 + source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(..., key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + - focus-metavariable: $SIZE + severity: WARNING +- fix: "SECP256R1\n" + id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + languages: + - python + message: Detected an insufficient curve size for EC. NIST recommends a key size of 224 or higher. For example, use + 'ec.SECP256R1'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves + semgrep.dev: + rule: + origin: community + r_id: 9448 + rule_id: qNUjZ3 + rv_id: 1263355 + url: + https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + version_id: RGT0LW6 + shortlink: https://sg.run/GeQq + source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...) + - pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE + - metavariable-pattern: + metavariable: $SIZE + pattern-either: + - pattern: SECP192R1 + - pattern: SECT163K1 + - pattern: SECT163R2 + - focus-metavariable: $SIZE + severity: WARNING +- fix: "2048\n" + id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + languages: + - python + message: Detected an insufficient key size for RSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + semgrep.dev: + rule: + origin: community + r_id: 9449 + rule_id: lBU9jn + rv_id: 1263356 + url: + https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + version_id: A8TgdPK + shortlink: https://sg.run/RoQq + source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(..., key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP, $SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + - focus-metavariable: $SIZE + severity: WARNING +- id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + languages: + - python + message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result + in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 31871 + rule_id: lBUpNZ + rv_id: 1263357 + url: + https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + version_id: BjTkZj5 + shortlink: https://sg.run/N9JL + source: + https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - patterns: + - pattern: "Cipher(..., $HAZMAT_MODE(...),...)\n" + - pattern-not-inside: "Cipher(..., $HAZMAT_MODE(...),...)\n...\nHMAC(...)\n" + - pattern-not-inside: "Cipher(..., $HAZMAT_MODE(...),...)\n...\nhmac.HMAC(...)\n" + - metavariable-pattern: + metavariable: $HAZMAT_MODE + patterns: + - pattern-either: + - pattern: modes.CTR + - pattern: modes.CBC + - pattern: modes.CFB + - pattern: modes.OFB + severity: ERROR +- fix: "True\n" + id: python.distributed.security.require-encryption + languages: + - python + message: Initializing a security context for Dask (`distributed`) without "require_encryption" keyword argument may + silently fail to provide security. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters + semgrep.dev: + rule: + origin: community + r_id: 9450 + rule_id: YGURy0 + rv_id: 1263358 + url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption + version_id: DkTRbol + shortlink: https://sg.run/AvQ2 + source: https://semgrep.dev/r/python.distributed.security.require-encryption + subcategory: + - vuln + technology: + - distributed + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: "distributed.security.Security(..., require_encryption=$VAL, ...)\n" + - metavariable-pattern: + metavariable: $VAL + pattern: "False\n" + - focus-metavariable: $VAL + severity: WARNING +- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + languages: + - python + message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`, `cpickle`, `dill`, `shelve`, or + `yaml`, which are known to lead to remote code execution vulnerabilities. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + semgrep.dev: + rule: + origin: community + r_id: 9467 + rule_id: OrU3e6 + rv_id: 1409400 + url: + https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + version_id: GxTlb9e + shortlink: https://sg.run/9oyr + source: + https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + subcategory: + - vuln + technology: + - django + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "pickle.$PICKLEFUNC(...)\n" + - pattern: "_pickle.$PICKLEFUNC(...)\n" + - pattern: "cPickle.$PICKLEFUNC(...)\n" + - pattern: "shelve.$PICKLEFUNC(...)\n" + - metavariable-regex: + metavariable: $PICKLEFUNC + regex: dumps|dump|load|loads + - patterns: + - pattern: dill.$DILLFUNC(...) + - metavariable-regex: + metavariable: $DILLFUNC + regex: dump|dump_session|dumps|load|load_session|loads + - patterns: + - pattern: yaml.$YAMLFUNC(...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...) + - metavariable-regex: + metavariable: $YAMLFUNC + regex: dump|dump_all|load|load_all + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: "def $INSIDE(..., $PARAM, ...):\n ...\n" + - pattern-either: + - pattern: request.$REQFUNC(...) + - pattern: request.$REQFUNC.get(...) + - pattern: request.$REQFUNC[...] + severity: ERROR +- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret + languages: + - python + message: The Django secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient + HashIDs, the salt used to construct them can be recovered. This means the Django secret key can be obtained by + attackers, through the HashIDs. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 – Cryptographic Failures + references: + - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + semgrep.dev: + rule: + origin: community + r_id: 72426 + rule_id: 0oUXqy + rv_id: 946163 + url: + https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret + version_id: 0bT15nn + shortlink: https://sg.run/bxeZ + source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) + - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) + severity: ERROR +- id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string + languages: + - python + message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute + remote code. See https://owasp.org/www-community/attacks/Code_Injection for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9500 + rule_id: BYUNw9 + rv_id: 1263383 + url: + https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + version_id: vdT06xG + shortlink: https://sg.run/4x2z + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: eval(..., $STR % request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., "..." % request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR % request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W(...)\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W[...]\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-eval.user-eval + languages: + - python + message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9501 + rule_id: DbUpDQ + rv_id: 1263384 + url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval + version_id: d6Tyx2A + shortlink: https://sg.run/PJDW + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: eval(..., request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $V, ...)\n" + - pattern: eval(..., request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $V, ...)\n" + - pattern: eval(..., request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $V, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string + languages: + - python + message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9502 + rule_id: WAUovx + rv_id: 1263385 + url: + https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + version_id: ZRTKA1p + shortlink: https://sg.run/J9JW + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: exec(..., $STR % request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., "..." % request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR % request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W(...)\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W[...]\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...), ...), ...) + - pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...), ...) + - pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...), ...), ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...", ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-exec.user-exec + languages: + - python + message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9503 + rule_id: 0oU5AW + rv_id: 1263386 + url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec + version_id: nWT2LA2 + shortlink: https://sg.run/5Q3X + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: exec(..., request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $V, ...)\n" + - pattern: exec(..., request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $V, ...)\n" + - pattern: exec(..., request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $V, ...)\n" + - pattern: "loop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, request.$W[...])\n" + - pattern: "$V = request.$W[...]\n...\nloop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, + $V)\n" + - pattern: "loop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, request.$W.get(...))\n" + - pattern: "$V = request.$W.get(...)\n...\nloop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, + $V)\n" + severity: WARNING +- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system + languages: + - python + message: Request data detected in os.system. This could be vulnerable to a command injection and should be avoided. If + this must be done, use the 'subprocess' module instead and pass the arguments as a list. See + https://owasp.org/www-community/attacks/Command_Injection for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + semgrep.dev: + rule: + origin: community + r_id: 9504 + rule_id: KxUbp2 + rv_id: 1263387 + url: + https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + version_id: ExTExPo + shortlink: https://sg.run/Gen2 + source: + https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: os.system(..., request.$W.get(...), ...) + - pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: os.system(..., $S % request.$W.get(...), ...) + - pattern: os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W.get(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W.get(...), ...) + - pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: return os.system(..., request.$W.get(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return os.system(..., $S % request.$W.get(...), ...) + - pattern: return os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: os.system(..., request.$W(...), ...) + - pattern: os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: os.system(..., $S % request.$W(...), ...) + - pattern: os.system(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W(...), ...) + - pattern: $A = os.system(..., f"...{request.$W(...)}...", ...) + - pattern: return os.system(..., request.$W(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return os.system(..., $S % request.$W(...), ...) + - pattern: return os.system(..., f"...{request.$W(...)}...", ...) + - pattern: os.system(..., request.$W[...], ...) + - pattern: os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: os.system(..., $S % request.$W[...], ...) + - pattern: os.system(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W[...], ...) + - pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = os.system(..., $S % request.$W[...], ...) + - pattern: $A = os.system(..., f"...{request.$W[...]}...", ...) + - pattern: return os.system(..., request.$W[...], ...) + - pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return os.system(..., $S % request.$W[...], ...) + - pattern: return os.system(..., f"...{request.$W[...]}...", ...) + - pattern: os.system(..., request.$W, ...) + - pattern: os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: os.system(..., $S % request.$W, ...) + - pattern: os.system(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W, ...) + - pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = os.system(..., $S % request.$W, ...) + - pattern: $A = os.system(..., f"...{request.$W}...", ...) + - pattern: return os.system(..., request.$W, ...) + - pattern: return os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: return os.system(..., $S % request.$W, ...) + - pattern: return os.system(..., f"...{request.$W}...", ...) + severity: ERROR +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection + vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them + to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the + command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a + dictionary to allowlist a set of commands. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 31144 + rule_id: EwUepx + rv_id: 1263388 + url: + https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + version_id: 7ZTE3qK + shortlink: https://sg.run/49BE + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: "$CMD = [\"...\", ...]\n...\nsubprocess.$FUNC($CMD, ...)\n" + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sources: + - patterns: + - pattern-inside: "def $FUNC(..., $REQUEST, ...):\n ...\n" + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + severity: ERROR +- id: python.django.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to + generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into + a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, + install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to + mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + semgrep.dev: + rule: + origin: community + r_id: 31145 + rule_id: 7KUK1y + rv_id: 1263389 + url: + https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection + version_id: LjTkgD9 + shortlink: https://sg.run/Pw9q + source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection + subcategory: + - vuln + technology: + - django + - python + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$WRITER = csv.writer(...)\n\n...\n\n$WRITER.$WRITE(...)\n" + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-inside: "def $FUNC(..., $REQUEST, ...):\n ...\n" + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + severity: ERROR +- id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body + languages: + - python + message: Found request data in an EmailMessage that is set to use HTML. This is dangerous because HTML emails are + susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + semgrep.dev: + rule: + origin: community + r_id: 9505 + rule_id: qNUj02 + rv_id: 1263390 + url: + https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + version_id: 8KT5rOn + shortlink: https://sg.run/RoBe + source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Other + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n $EMAIL.content_subtype = \"html\"\n ...\n" + - pattern-either: + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...) + severity: WARNING +- id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + languages: + - python + message: Found request data in 'send_mail(...)' that uses 'html_message'. This is dangerous because HTML emails are + susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + semgrep.dev: + rule: + origin: community + r_id: 9506 + rule_id: lBU9Ll + rv_id: 1263391 + url: + https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + version_id: gETB7Gn + shortlink: https://sg.run/Avx8 + source: + https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Other + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...) + severity: WARNING +- id: python.django.security.injection.open-redirect.open-redirect + languages: + - python + message: Data from request ($DATA) is passed to redirect(). This is an open redirect and could be exploited. Ensure + you are redirecting to safe URLs by using django.utils.http.is_safe_url(). See + https://cwe.mitre.org/data/definitions/601.html for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/ + - https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231 + semgrep.dev: + rule: + origin: community + r_id: 9494 + rule_id: PeUZgr + rv_id: 1263393 + url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect + version_id: 3ZT4XD7 + shortlink: https://sg.run/Ave2 + source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Open Redirect + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n django.utils.http.is_safe_url(...)\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n if <... django.utils.http.is_safe_url(...) ...>:\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n django.utils.http.url_has_allowed_host_and_scheme(...)\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>:\n\ + \ ...\n" + - pattern-either: + - pattern: django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W, ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W, ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - metavariable-regex: + metavariable: $W + regex: (?!get_full_path) + severity: WARNING +- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + languages: + - python + message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could + result in path traversal attacks and therefore sensitive data being leaked. To mitigate, consider using + os.path.abspath or os.path.realpath or the pathlib library. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9509 + rule_id: oqUe7z + rv_id: 1263396 + url: + https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + version_id: JdTzxAw + shortlink: https://sg.run/W8qg + source: + https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Path Traversal + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: open(..., request.$W.get(...), ...) + - pattern: open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: open(..., $S % request.$W.get(...), ...) + - pattern: open(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) + as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n\ + \ ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W.get(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = open(..., $S % request.$W.get(...), ...) + - pattern: $A = open(..., f"...{request.$W.get(...)}...", ...) + - pattern: return open(..., request.$W.get(...), ...) + - pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return open(..., $S % request.$W.get(...), ...) + - pattern: return open(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W(...), ...) + - pattern: open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: open(..., $S % request.$W(...), ...) + - pattern: open(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as + $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = open(..., $S % request.$W(...), ...) + - pattern: $A = open(..., f"...{request.$W(...)}...", ...) + - pattern: return open(..., request.$W(...), ...) + - pattern: return open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return open(..., $S % request.$W(...), ...) + - pattern: return open(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W[...], ...) + - pattern: open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: open(..., $S % request.$W[...], ...) + - pattern: open(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as + $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W[...], ...) + - pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = open(..., $S % request.$W[...], ...) + - pattern: $A = open(..., f"...{request.$W[...]}...", ...) + - pattern: return open(..., request.$W[...], ...) + - pattern: return open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return open(..., $S % request.$W[...], ...) + - pattern: return open(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W, ...) + - pattern: open(..., $S.format(..., request.$W, ...), ...) + - pattern: open(..., $S % request.$W, ...) + - pattern: open(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as $FD:\n\ + \ ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W, ...) + - pattern: $A = open(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = open(..., $S % request.$W, ...) + - pattern: $A = open(..., f"...{request.$W}...", ...) + - pattern: return open(..., request.$W, ...) + - pattern: return open(..., $S.format(..., request.$W, ...), ...) + - pattern: return open(..., $S % request.$W, ...) + - pattern: return open(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + severity: WARNING +- id: python.django.security.injection.raw-html-format.raw-html-format + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates (`django.shortcuts.render`) which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render + - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection + semgrep.dev: + rule: + origin: community + r_id: 14360 + rule_id: 2ZUPER + rv_id: 1263397 + url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format + version_id: 5PTo100 + shortlink: https://sg.run/oYj1 + source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: django.utils.html.escape(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + severity: WARNING +- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + languages: + - python + message: Found user-controlled request data passed into HttpResponse. This could be vulnerable to XSS, leading to + attackers gaining access to user cookies and protected information. Ensure that the request data is properly escaped + or sanitzed. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9495 + rule_id: JDUydR + rv_id: 1263398 + url: + https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + version_id: GxTke5K + shortlink: https://sg.run/BkvA + source: + https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponse(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W[...], ...) + - pattern: return django.http.HttpResponse(..., request.$W[...], ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W, ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$A = django.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: return django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + languages: + - python + message: Found user-controlled request data passed into a HttpResponseBadRequest. This could be vulnerable to XSS, + leading to attackers gaining access to user cookies and protected information. Ensure that the request data is + properly escaped or sanitzed. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9496 + rule_id: 5rUOX1 + rv_id: 1263399 + url: + https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + version_id: RGT0LY6 + shortlink: https://sg.run/DoZP + source: + https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse + languages: + - python + message: Found user-controlled request data being passed into a file open, which is them passed as an argument into + the FileResponse. This is dangerous because an attacker could specify an arbitrary file to read, which could result + in leaking important data. Be sure to validate or sanitize the user-inputted filename in the request data before + using it in FileResponse. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9497 + rule_id: GdU7QR + rv_id: 1263400 + url: + https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + version_id: A8Tgd1K + shortlink: https://sg.run/W862 + source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Path Traversal + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, + ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: return django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: django.http.FileResponse(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W(...), ...) + - pattern: return django.http.FileResponse(..., request.$W(...), ...) + - pattern: django.http.FileResponse(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W[...], ...) + - pattern: return django.http.FileResponse(..., request.$W[...], ...) + - pattern: django.http.FileResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W, ...) + - pattern: return django.http.FileResponse(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.request-data-write.request-data-write + languages: + - python + message: Found user-controlled request data passed into '.write(...)'. This could be dangerous if a malicious actor is + able to control data into sensitive files. For example, a malicious actor could force rolling of critical log files, + or cause a denial-of-service by using up available disk space. Instead, ensure that request data is properly escaped + or sanitized. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9498 + rule_id: ReUg5z + rv_id: 1263401 + url: + https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write + version_id: BjTkZO5 + shortlink: https://sg.run/0Q6j + source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Validation + pattern-either: + - pattern: $F.write(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W.get(...), ...) + - pattern: return $F.write(..., request.$W.get(...), ...) + - pattern: $F.write(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W(...), ...) + - pattern: return $F.write(..., request.$W(...), ...) + - pattern: $F.write(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W[...], ...) + - pattern: return $F.write(..., request.$W[...], ...) + - pattern: $F.write(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W, ...) + - pattern: return $F.write(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + languages: + - python + message: User-controlled data from a request is passed to 'extra()'. This could lead to a SQL injection and therefore + protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by + using `params` and not using quote placeholders in the SQL string. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra + semgrep.dev: + rule: + origin: community + r_id: 9510 + rule_id: zdUkx1 + rv_id: 1263402 + url: + https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + version_id: DkTRb4l + shortlink: https://sg.run/0Ql5 + source: + https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...), ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...), ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...], ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + languages: + - python + message: User-controlled data from request is passed to 'RawSQL()'. This could lead to a SQL injection and therefore + protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by + using `params` and not using quote placeholders in the SQL string. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL + semgrep.dev: + rule: + origin: community + r_id: 9511 + rule_id: pKUOBp + rv_id: 1263403 + url: + https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + version_id: WrTqK2L + shortlink: https://sg.run/Kl4X + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W, ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + languages: + - python + message: User-controlled data from a request is passed to 'execute()'. This could lead to a SQL injection and + therefore protected information could be leaked. Instead, use django's QuerySets, which are built with query + parameterization and therefore not vulnerable to sql injection. For example, you could use + `Entry.objects.filter(date=2006)`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + semgrep.dev: + rule: + origin: community + r_id: 9512 + rule_id: 2ZUbDL + rv_id: 1263404 + url: + https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + version_id: 0bTKzRj + shortlink: https://sg.run/qx7y + source: + https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: return $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W(...), ...) + - pattern: return $CURSOR.execute(..., request.$W(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W[...], ...) + - pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...) + - pattern: $CURSOR.execute(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W[...], ...) + - pattern: return $CURSOR.execute(..., request.$W[...], ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W, ...) + - pattern: $CURSOR.execute(..., f"...{request.$W}...", ...) + - pattern: $CURSOR.execute(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W, ...) + - pattern: return $CURSOR.execute(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + languages: + - python + message: Data that is possible user-controlled from a python request is passed to `raw()`. This could lead to SQL + injection and attackers gaining access to protected information. Instead, use django's QuerySets, which are built + with query parameterization and therefore not vulnerable to sql injection. For example, you could use + `Entry.objects.filter(date=2006)`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + semgrep.dev: + rule: + origin: community + r_id: 9513 + rule_id: X5U8v5 + rv_id: 1263405 + url: + https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + version_id: K3TKkBW + shortlink: https://sg.run/l2v9 + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: return $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W, ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W, ...) + - pattern: return $MODEL.objects.raw(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the + response to the user, and ensure proper authentication and transport-layer security in the proxied request. See + https://owasp.org/www-community/attacks/Server_Side_Request_Forgery to learn more about SSRF vulnerabilities. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9514 + rule_id: j2UvEw + rv_id: 1263406 + url: + https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + version_id: qkTR7zn + shortlink: https://sg.run/YvY4 + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Server-Side Request Forgery (SSRF) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W.get(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W.get(...), ...) + - pattern: return requests.$METHOD(..., request.$W.get(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W(...), ...) + - pattern: return requests.$METHOD(..., request.$W(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W[...], ...) + - pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...) + - pattern: requests.$METHOD(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W[...], ...) + - pattern: return requests.$METHOD(..., request.$W[...], ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W, ...) + - pattern: requests.$METHOD(..., f"...{request.$W}...", ...) + - pattern: requests.$METHOD(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W, ...) + - pattern: return requests.$METHOD(..., request.$W, ...) + severity: ERROR +- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF), which could result in attackers gaining access to private organization data. To mitigate, ensure + that schemes and hosts are validated against an allowlist, do not forward the response to the user, and ensure + proper authentication and transport-layer security in the proxied request. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9515 + rule_id: 10UKDo + rv_id: 1263407 + url: + https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + version_id: l4TJRwD + shortlink: https://sg.run/6n2B + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Server-Side Request Forgery (SSRF) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W[...], ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...) + - pattern: urllib.request.urlopen(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W[...], ...) + - pattern: return urllib.request.urlopen(..., request.$W[...], ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W, ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...) + - pattern: urllib.request.urlopen(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W, ...) + - pattern: return urllib.request.urlopen(..., request.$W, ...) + severity: ERROR +- id: python.django.security.passwords.password-empty-string.password-empty-string + languages: + - python + message: "'$VAR' is the empty string and is being used to set the password on '$MODEL'. If you meant to set an unusable + password, set the password to None or call 'set_unusable_password()'." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-521: Weak Password Requirements' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + semgrep.dev: + rule: + origin: community + r_id: 9516 + rule_id: 9AU1jW + rv_id: 1263411 + url: + https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string + version_id: GxTke5Q + shortlink: https://sg.run/oxnR + source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: "$MODEL.set_password($EMPTY)\n...\n$MODEL.save()\n" + - pattern: "$VAR = $EMPTY\n...\n$MODEL.set_password($VAR)\n...\n$MODEL.save()\n" + - metavariable-regex: + metavariable: $EMPTY + regex: (\'\'|\"\") + severity: ERROR +- fix: "None\n" + id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + languages: + - python + message: "'$VAR' is using the empty string as its default and is being used to set the password on '$MODEL'. If you meant + to set an unusable password, set the default value to 'None' or call 'set_unusable_password()'." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-521: Weak Password Requirements' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + semgrep.dev: + rule: + origin: community + r_id: 9517 + rule_id: yyUn6Z + rv_id: 1263412 + url: + https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + version_id: RGT0LYX + shortlink: https://sg.run/zvBW + source: + https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: "$VAR = request.$W.get($X, $EMPTY)\n...\n$MODEL.set_password($VAR)\n...\n$MODEL.save(...)\n" + - pattern: "def $F(..., $VAR=$EMPTY, ...):\n ...\n $MODEL.set_password($VAR)\n" + - metavariable-pattern: + metavariable: $EMPTY + pattern: '""' + - focus-metavariable: $EMPTY + severity: ERROR +- id: python.fastapi.security.wildcard-cors.wildcard-cors + languages: + - python + message: CORS policy allows any origin (using wildcard '*'). This is insecure and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + - https://cwe.mitre.org/data/definitions/942.html + semgrep.dev: + rule: + origin: community + r_id: 112311 + rule_id: lBU4JQ3 + rv_id: 1263413 + url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors + version_id: A8Tgd1R + shortlink: https://sg.run/KxApY + source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors + subcategory: + - vuln + technology: + - python + - fastapi + vulnerability_class: + - Configuration + mode: taint + pattern-sinks: + - patterns: + - pattern: "$APP.add_middleware(\n CORSMiddleware,\n allow_origins=$ORIGIN,\n ...);\n" + - focus-metavariable: $ORIGIN + pattern-sources: + - pattern: '[..., "*", ...]' + severity: WARNING +- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + languages: + - python + message: Running flask app with host 0.0.0.0 could expose the server publicly. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9532 + rule_id: L1Uy1n + rv_id: 1263414 + url: + https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + version_id: BjTkZOY + shortlink: https://sg.run/eLby + source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Other + pattern-either: + - pattern: app.run(..., host="0.0.0.0", ...) + - pattern: app.run(..., "0.0.0.0", ...) + severity: WARNING +- id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + languages: + - python + message: top-level app.run(...) is ignored by flask. Consider putting app.run(...) behind a guard, like inside a + function + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9533 + rule_id: 8GUjdX + rv_id: 1263415 + url: + https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + version_id: DkTRb4z + shortlink: https://sg.run/vz5b + source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Other + patterns: + - pattern-not-inside: "if __name__ == '__main__':\n ...\n" + - pattern-not-inside: "def $X(...):\n ...\n" + - pattern: app.run(...) + severity: WARNING +- id: python.flask.security.audit.debug-enabled.debug-enabled + languages: + - python + message: Detected Flask app with debug=True. Do not deploy to production with this flag enabled as it will leak + sensitive information. Instead, consider using Flask configuration variables or setting 'debug' using system + environment variables. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-489: Active Debug Code' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: A06:2017 - Security Misconfiguration + references: + - https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ + semgrep.dev: + rule: + origin: community + r_id: 9534 + rule_id: gxU1bd + rv_id: 946206 + url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled + version_id: 8KTKjwR + shortlink: https://sg.run/dKrd + source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Active Debug Code + patterns: + - pattern-inside: "import flask\n...\n" + - pattern: $APP.run(..., debug=True, ...) + severity: WARNING +- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + languages: + - python + message: Detected Flask route directly returning a formatted string. This is subject to cross-site scripting if user + input can reach the string. Consider using the template engine instead and rendering pages with 'render_template()'. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9535 + rule_id: QrUz49 + rv_id: 1263416 + url: + https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + version_id: WrTqKAz + shortlink: https://sg.run/Zv6o + source: + https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-not-inside: return "..." + - pattern-either: + - pattern: return "...".format(...) + - pattern: return "..." % ... + - pattern: return "..." + ... + - pattern: return ... + "..." + - pattern: return f"...{...}..." + - patterns: + - pattern: return $X + - pattern-either: + - pattern-inside: "$X = \"...\".format(...)\n...\n" + - pattern-inside: "$X = \"...\" % ...\n...\n" + - pattern-inside: "$X = \"...\" + ...\n...\n" + - pattern-inside: "$X = ... + \"...\"\n...\n" + - pattern-inside: "$X = f\"...{...}...\"\n...\n" + - pattern-not-inside: "$X = \"...\"\n...\n" + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $PARAM, ...):\n ...\n" + - pattern: $PARAM + - pattern: "request.$FUNC.get(...)\n" + - pattern: "request.$FUNC(...)\n" + - pattern: request.$FUNC[...] + severity: WARNING +- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + languages: + - python + message: Function `flask.url_for` with `_external=True` argument will generate URLs using the `Host` header of the + HTTP request, which may lead to security risks such as Host header injection + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-673: External Influence of Sphere Definition' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/latest/api/#flask.url_for + - https://portswigger.net/kb/issues/00500300_host-header-injection + semgrep.dev: + rule: + origin: community + r_id: 191541 + rule_id: JDU5oql + rv_id: 1263418 + url: + https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + version_id: K3TKk6n + shortlink: https://sg.run/gEGeR + source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Other + patterns: + - pattern-not: flask.url_for(..., _external=False, ...) + - pattern-not: url_for(..., _external=False, ...) + - pattern-either: + - pattern: flask.url_for(..., _external=$VAR, ...) + - pattern: url_for(..., _external=$VAR, ...) + severity: WARNING +- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + languages: + - python + message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient + HashIDs, the salt used to construct them can be recovered. This means the Flask secret key can be obtained by + attackers, through the HashIDs. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 – Cryptographic Failures + references: + - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + semgrep.dev: + rule: + origin: community + r_id: 72427 + rule_id: KxUX3z + rv_id: 946220 + url: + https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + version_id: 0bT15Px + shortlink: https://sg.run/N0Rx + source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) + - patterns: + - pattern-inside: "$APP = flask.Flask(...)\n...\n" + - pattern-either: + - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) + severity: ERROR +- id: python.flask.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to + generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into + a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, + install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to + mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + semgrep.dev: + rule: + origin: community + r_id: 31146 + rule_id: L1UR2K + rv_id: 1263428 + url: + https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection + version_id: jQTn50Y + shortlink: https://sg.run/JzqQ + source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection + subcategory: + - vuln + technology: + - python + - flask + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$WRITER = csv.writer(...)\n\n...\n\n$WRITER.$WRITE(...)\n" + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.os-system-injection.os-system-injection + languages: + - python + message: User data detected in os.system. This could be vulnerable to a command injection and should be avoided. If + this must be done, use the 'subprocess' module instead and pass the arguments as a list. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + semgrep.dev: + rule: + origin: community + r_id: 9544 + rule_id: BYUN99 + rv_id: 1263429 + url: + https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection + version_id: 1QTypw7 + shortlink: https://sg.run/4xzz + source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Command Injection + pattern-either: + - patterns: + - pattern: os.system(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n os.system(..., <... $ROUTEVAR + ...>, ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n os.system(..., <... $INTERM ...>, ...)\n" + - pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W[...] ...>, ...) + - pattern: os.system(..., <... flask.request.$W(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + severity: ERROR +- id: python.flask.security.injection.path-traversal-open.path-traversal-open + languages: + - python + message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could + result in path traversal attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9545 + rule_id: DbUpOQ + rv_id: 1263430 + url: + https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open + version_id: 9lT4b94 + shortlink: https://sg.run/PJRW + source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Path Traversal + pattern-either: + - patterns: + - pattern: open(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n open(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n with open(..., <... $ROUTEVAR + ...>, ...) as $FD:\n ...\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n open(..., <... $INTERM ...>, ...)\n" + - pattern: open(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: open(..., <... flask.request.$W[...] ...>, ...) + - pattern: open(..., <... flask.request.$W(...) ...>, ...) + - pattern: open(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + severity: ERROR +- id: python.flask.security.injection.raw-html-concat.raw-html-format + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates (`flask.render_template`) which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 14389 + rule_id: GdUrJv + rv_id: 1409401 + url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format + version_id: RGTEN1l + shortlink: https://sg.run/Pb7e + source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: jinja2.escape(...) + - pattern: flask.escape(...) + - patterns: + - pattern: flask.render_template($TPL, ...) + - metavariable-regex: + metavariable: $TPL + regex: .*\.html + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: WARNING +- id: python.flask.security.injection.ssrf-requests.ssrf-requests + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the + response to the user, and ensure proper authentication and transport-layer security in the proxied request. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9546 + rule_id: WAUoRx + rv_id: 1263432 + url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests + version_id: rxTAKJn + shortlink: https://sg.run/J9LW + source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Server-Side Request Forgery (SSRF) + pattern-either: + - patterns: + - pattern: requests.$FUNC(...) + - pattern-either: + - pattern-inside: "@$APP.$ROUTE_METHOD($ROUTE, ...)\ndef $ROUTE_FUNC(..., $ROUTEVAR, ...):\n ...\n requests.$FUNC(..., + <... $ROUTEVAR ...>, ...)\n" + - pattern-inside: "@$APP.$ROUTE_METHOD($ROUTE, ...)\ndef $ROUTE_FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... + $ROUTEVAR ...>\n ...\n requests.$FUNC(..., <... $INTERM ...>, ...)\n" + - metavariable-regex: + metavariable: $ROUTE_METHOD + regex: ^(route|get|post|put|delete|patch)$ + - pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + severity: ERROR +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection + vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them + to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the + command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a + dictionary to allowlist a set of commands. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 31147 + rule_id: 8GU3qp + rv_id: 1263433 + url: + https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + version_id: bZT53gQ + shortlink: https://sg.run/5gW3 + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: "$CMD = [\"...\", ...]\n...\nsubprocess.$FUNC($CMD, ...)\n" + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as SQLAlchemy which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column + semgrep.dev: + rule: + origin: community + r_id: 14702 + rule_id: YGUDKQ + rv_id: 1409402 + url: + https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string + version_id: A8TEvb4 + shortlink: https://sg.run/JxZj + source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - sqlalchemy + - flask + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\" % ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - pattern: "f\"$SQLSTR{...}...\"\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send + data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with + this request. They could also probe internal servers or other resources that the server running this code can + access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an + allowlist for approved hosts, or hardcode the correct host. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 14649 + rule_id: ReU3Wb + rv_id: 1409403 + url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host + version_id: BjTy42w + shortlink: https://sg.run/RXpK + source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + language: generic + metavariable: $URLSTR + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + language: generic + metavariable: $URLSTR + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: "$URL = \"$URLSTR\"\n...\n" + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: WARNING +- id: python.flask.security.injection.user-eval.eval-injection + languages: + - python + message: Detected user data flowing into eval. This is code injection and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9547 + rule_id: 0oU54W + rv_id: 1263436 + url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection + version_id: w8TRoB0 + shortlink: https://sg.run/5QpX + source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Code Injection + pattern-either: + - patterns: + - pattern: eval(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n eval(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n eval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W[...] ...>, ...) + - pattern: eval(..., <... flask.request.$W(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + severity: ERROR +- id: python.flask.security.injection.user-exec.exec-injection + languages: + - python + message: Detected user data flowing into exec. This is code injection and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9548 + rule_id: KxUbl2 + rv_id: 1263437 + url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection + version_id: xyTjzD9 + shortlink: https://sg.run/Ge42 + source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Code Injection + pattern-either: + - patterns: + - pattern: exec(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n exec(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n exec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W[...] ...>, ...) + - pattern: exec(..., <... flask.request.$W(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + severity: ERROR +- fix: "True\n" + id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + languages: + - python + message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous if you are rendering to a + browser because this allows for cross-site scripting (XSS) attacks. If you are in a web context, enable + 'autoescaping' by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' to only enable + automatic escaping for certain file extensions. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + semgrep.dev: + rule: + origin: community + r_id: 20039 + rule_id: QrU1Xg + rv_id: 1263448 + url: + https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + version_id: gETB7oN + shortlink: https://sg.run/L2L7 + source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + subcategory: + - vuln + technology: + - jinja2 + vulnerability_class: + - Improper Encoding + patterns: + - pattern: jinja2.Environment(... , autoescape=$VAL, ...) + - pattern-not: jinja2.Environment(... , autoescape=True, ...) + - pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...), ...) + - focus-metavariable: $VAL + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, autoescape=True) + id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + languages: + - python + message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape by default. This is dangerous + if you are rendering to a browser because this allows for cross-site scripting (XSS) attacks. If you are in a web + context, enable autoescaping by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' + to only enable automatic escaping for certain file extensions. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + semgrep.dev: + rule: + origin: community + r_id: 20040 + rule_id: 3qULRx + rv_id: 1263449 + url: + https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + version_id: QkTGqje + shortlink: https://sg.run/8kY4 + source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + subcategory: + - vuln + technology: + - jinja2 + vulnerability_class: + - Improper Encoding + patterns: + - pattern-not: jinja2.Environment(..., autoescape=$VAL, ...) + - pattern: jinja2.Environment(...) + severity: WARNING +- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + languages: + - python + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + semgrep.dev: + rule: + origin: community + r_id: 9557 + rule_id: X5U8P5 + rv_id: 1263452 + url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + version_id: PkTR3X3 + shortlink: https://sg.run/l2E9 + source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "jwt.encode($_, \"...\", ...)\n" + severity: ERROR +- id: python.jwt.security.jwt-none-alg.jwt-python-none-alg + languages: + - python + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9558 + rule_id: j2UvKw + rv_id: 1263453 + url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg + version_id: JdTzxYj + shortlink: https://sg.run/Yvp4 + source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "jwt.encode(...,algorithm=\"none\",...)\n" + - pattern: jwt.decode(...,algorithms=[...,"none",...],...) + severity: ERROR +- fix: "True\n" + id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + languages: + - python + message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity checks for the token which means + the token could be tampered with by malicious actors. Ensure that the JWT token is verified. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-287: Improper Authentication' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96 + semgrep.dev: + rule: + origin: community + r_id: 9559 + rule_id: 10UKjo + rv_id: 1263454 + url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + version_id: 5PTo12w + shortlink: https://sg.run/6nyB + source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - patterns: + - pattern: "jwt.decode(..., options={..., \"verify_signature\": $BOOL, ...}, ...)\n" + - metavariable-pattern: + metavariable: $BOOL + pattern: "False\n" + - focus-metavariable: $BOOL + - patterns: + - pattern: "$OPTS = {..., \"verify_signature\": $BOOL, ...}\n...\njwt.decode(..., options=$OPTS, ...)\n" + - metavariable-pattern: + metavariable: $BOOL + pattern: "False\n" + - focus-metavariable: $BOOL + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + languages: + - python + message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled data. You may consider using + 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27250 + rule_id: 7KUE1E + rv_id: 1263460 + url: + https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + version_id: WrTqKXz + shortlink: https://sg.run/Apjp + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...) + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...) + - pattern: $LOOP.subprocess_exec(...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c",...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", ...], ...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + languages: + - python + message: Detected asyncio subprocess function with user controlled data. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27252 + rule_id: 8GU5q3 + rv_id: 1263462 + url: + https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + version_id: K3TKkDn + shortlink: https://sg.run/Dx8Y + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern-inside: asyncio.create_subprocess_shell($CMD, ...) + - focus-metavariable: $CMD + - pattern-not-inside: "$CMD = \"...\"\n...\n" + - pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...") + - pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...) + - pattern-not: asyncio.create_subprocess_shell("...", ...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + languages: + - python + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if + external data can reach this function call because it allows a malicious actor to run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27254 + rule_id: QrUG72 + rv_id: 1263464 + url: + https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + version_id: l4TJRK9 + shortlink: https://sg.run/0Bgv + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$X = code.InteractiveConsole(...)\n...\n" + - pattern-inside: "$X = code.InteractiveInterpreter(...)\n...\n" + - pattern-either: + - pattern-inside: "$X.push($PAYLOAD,...)\n" + - pattern-inside: "$X.runsource($PAYLOAD,...)\n" + - pattern-inside: "$X.runcode(code.compile_command($PAYLOAD),...)\n" + - pattern-inside: "$PL = code.compile_command($PAYLOAD,...)\n...\n$X.runcode($PL,...)\n" + - pattern: $PAYLOAD + - pattern-not: "$X.push(\"...\",...)\n" + - pattern-not: "$X.runsource(\"...\",...)\n" + - pattern-not: "$X.runcode(code.compile_command(\"...\"),...)\n" + - pattern-not: "$PL = code.compile_command(\"...\",...)\n...\n$X.runcode($PL,...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27256 + rule_id: 4bUEAY + rv_id: 1263466 + url: + https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + version_id: 6xT29l6 + shortlink: https://sg.run/qL6z + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27258 + rule_id: JDUz34 + rv_id: 1263468 + url: + https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + version_id: zyTb2wn + shortlink: https://sg.run/Y3Ke + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: + python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + languages: + - python + message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run + arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27260 + rule_id: GdUkxO + rv_id: 1409404 + url: + https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + version_id: DkTwBzO + shortlink: https://sg.run/oLl9 + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-inside: "_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)\n" + - pattern-not: "_xxsubinterpreters.run_string($ID, \"...\", ...)\n" + - pattern: $PAYLOAD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + languages: + - python + message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to + perform command injection. You may consider using 'shlex.quote()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27262 + rule_id: AbUgrZ + rv_id: 1263472 + url: + https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + version_id: jQTn54Y + shortlink: https://sg.run/pLGg + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - pattern: shlex.quote(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + languages: + - python + message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use + the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection + vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27264 + rule_id: DbUR9g + rv_id: 1263474 + url: + https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + version_id: 9lT4bG4 + shortlink: https://sg.run/XR2K + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: "$X = __import__(\"os\")\n...\n$X.system(...)\n" + - pattern: "$X = __import__(\"os\")\n...\ngetattr($X, \"system\")(...)\n" + - pattern: "$X = getattr(os, \"system\")\n...\n$X(...)\n" + - pattern: "$X = __import__(\"os\")\n...\n$Y = getattr($X, \"system\")\n...\n$Y(...)\n" + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: + python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + languages: + - python + message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to + run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27266 + rule_id: 0oUK7N + rv_id: 1263476 + url: + https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + version_id: rxTAKpn + shortlink: https://sg.run/1DLw + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "_testcapi.run_in_subinterp($PAYLOAD, ...)\n" + - pattern-inside: "test.support.run_in_subinterp($PAYLOAD, ...)\n" + - pattern: $PAYLOAD + - pattern-not: "_testcapi.run_in_subinterp(\"...\", ...)\n" + - pattern-not: "test.support.run_in_subinterp(\"...\", ...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + languages: + - python + message: These permissions `$BITS` are widely permissive and grant access to more people than may be necessary. A good + default is `0o644` which gives read and write access to yourself and read access to everyone else. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-276: Incorrect Default Permissions' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 13594 + rule_id: zdUYqR + rv_id: 1263482 + url: + https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + version_id: O9Tpxqr + shortlink: https://sg.run/AXY4 + source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: os.$METHOD(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: chmod + - pattern: lchmod + - pattern: fchmod + - pattern-either: + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-comparison: + comparison: $BITS >= 0o650 and $BITS < 0o100000 + metavariable: $BITS + - patterns: + - pattern: os.$METHOD($FILE, $BITS) + - metavariable-comparison: + comparison: $BITS >= 0o100650 + metavariable: $BITS + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-pattern: + metavariable: $BITS + patterns: + - pattern-either: + - pattern: <... stat.S_IWGRP ...> + - pattern: <... stat.S_IXGRP ...> + - pattern: <... stat.S_IWOTH ...> + - pattern: <... stat.S_IXOTH ...> + - pattern: <... stat.S_IRWXO ...> + - pattern: <... stat.S_IRWXG ...> + - patterns: + - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) + - metavariable-comparison: + comparison: $MOD == 0o111 + metavariable: $MOD + severity: WARNING +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: + python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. + metadata: + asvs: + control_id: 9.2.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9651 + rule_id: lBU9BZ + rv_id: 1263484 + url: + https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + version_id: vdT06wb + shortlink: https://sg.run/Bk5W + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-inside: "with requests.Session(...) as $SESSION:\n ...\n" + - pattern-either: + - pattern: $SESSION.$W($SINK, ...) + - pattern: $SESSION.request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. + metadata: + asvs: + control_id: 9.1.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9652 + rule_id: YGURXw + rv_id: 1263485 + url: + https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + version_id: d6Tyx02 + shortlink: https://sg.run/DoBY + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.Session(...).$W($SINK, ...) + - pattern: requests.Session(...).request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted, and attackers could listen into traffic + on the network and be able to obtain sensitive information. Use 'https://' instead. + metadata: + asvs: + control_id: 9.1.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9653 + rule_id: 6JUjpG + rv_id: 1263486 + url: + https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + version_id: ZRTKA9v + shortlink: https://sg.run/W8J4 + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.$W($SINK, ...) + - pattern: requests.request($METHOD, $SINK, ...) + - pattern: requests.Request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + languages: + - python + message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING being logged. This may lead to + secret credentials being exposed. Make sure that the logger is not logging sensitive information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-532: Insertion of Sensitive Information into Log File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures + semgrep.dev: + rule: + origin: community + r_id: 9668 + rule_id: x8UnJk + rv_id: 1263501 + url: + https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + version_id: A8TgdOR + shortlink: https://sg.run/ydNx + source: + https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: "$LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...)\n" + - metavariable-regex: + metavariable: $LOGGER_OBJ + regex: (?i)(_logger|logger|self.logger|log) + - metavariable-regex: + metavariable: $LOGGER_CALL + regex: (debug|info|warn|warning|error|exception|critical) + - metavariable-regex: + metavariable: $FORMAT_STRING + regex: (?i).*(api.key|secret|credential|token|password).*\%s.* + severity: WARNING +- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - python + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as scrypt. You can + use `hashlib.scrypt`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt + semgrep.dev: + rule: + origin: community + r_id: 14703 + rule_id: 6JU1w1 + rv_id: 1263504 + url: + https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: WrTqKDz + shortlink: https://sg.run/5DwD + source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - pycryptodome + - hashlib + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: hashlib.md5 + - pattern: hashlib.new(..., name="MD5", ...) + - pattern: Cryptodome.Hash.MD5 + - pattern: Crypto.Hash.MD5 + - pattern: cryptography.hazmat.primitives.hashes.MD5 + severity: WARNING +- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + languages: + - python + message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds + to all available interfaces. Consider instead getting correct address from an environment variable or configuration + file. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9669 + rule_id: OrU3og + rv_id: 1263505 + url: + https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + version_id: 0bTKzDL + shortlink: https://sg.run/rdln + source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"0.0.0.0\", ...))\n" + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"::\", ...))\n" + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"\", ...))\n" + severity: INFO +- id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + languages: + - python + message: certificate verification explicitly disabled, insecure connections possible + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 9670 + rule_id: eqU87k + rv_id: 1263506 + url: + https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + version_id: K3TKkZn + shortlink: https://sg.run/b7yp + source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...) + - pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...) + - pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...) + - pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...) + - metavariable-regex: + metavariable: $REQS + regex: + (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\") + severity: ERROR +- id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + languages: + - python + message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is recommended to use + HTTPSConnectionPool instead for to encrypt communications. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool + semgrep.dev: + rule: + origin: community + r_id: 9671 + rule_id: v8UnWQ + rv_id: 1263507 + url: + https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + version_id: qkTR7E1 + shortlink: https://sg.run/N4Np + source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + subcategory: + - audit + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: urllib3.HTTPConnectionPool(...) + - pattern: urllib3.connectionpool.HTTPConnectionPool(...) + severity: ERROR +- id: python.lang.security.audit.sha224-hash.sha224-hash + languages: + - python + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151752 + rule_id: BYUX0y9 + rv_id: 1263511 + url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash + version_id: 5PTo1QL + shortlink: https://sg.run/Db1Yv + source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashlib.sha224(...) + - pattern: hashlib.sha3_224(...) + severity: WARNING +- id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + languages: + - python + message: "'ssl.wrap_socket()' is deprecated. This function creates an insecure socket without server name indication or + hostname matching. Instead, create an SSL context using 'ssl.SSLContext()' and use that to wrap a socket." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://docs.python.org/3/library/ssl.html#ssl.wrap_socket + - https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket + semgrep.dev: + rule: + origin: community + r_id: 9645 + rule_id: BYUN2e + rv_id: 1263516 + url: + https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + version_id: DkTRbgn + shortlink: https://sg.run/PJOY + source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern: ssl.wrap_socket(...) + severity: WARNING +- fix: "False\n" + id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + languages: + - python + message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the + command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier + for a malicious actor to execute commands. Use 'shell=False' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + semgrep.dev: + rule: + origin: community + r_id: 9646 + rule_id: DbUpz2 + rv_id: 1263518 + url: + https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + version_id: 0bTKzDK + shortlink: https://sg.run/J92w + source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html + subcategory: + - secure default + technology: + - python + vulnerability_class: + - Command Injection + patterns: + - pattern: subprocess.$FUNC(..., shell=$TRUE, ...) + - metavariable-pattern: + metavariable: $TRUE + pattern: "True \n" + - pattern-not: subprocess.$FUNC("...", shell=True, ...) + - focus-metavariable: $TRUE + severity: ERROR +- id: python.lang.security.audit.weak-ssl-version.weak-ssl-version + languages: + - python + message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak + encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2' or higher. + metadata: + asvs: + control_id: 9.1.3 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + - https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2 + semgrep.dev: + rule: + origin: community + r_id: 9649 + rule_id: KxUbNG + rv_id: 1263520 + url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version + version_id: qkTR7Ev + shortlink: https://sg.run/RoZO + source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30 + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: ssl.PROTOCOL_SSLv2 + - pattern: ssl.PROTOCOL_SSLv3 + - pattern: ssl.PROTOCOL_TLSv1 + - pattern: ssl.PROTOCOL_TLSv1_1 + - pattern: pyOpenSSL.SSL.SSLv2_METHOD + - pattern: pyOpenSSL.SSL.SSLv23_METHOD + - pattern: pyOpenSSL.SSL.SSLv3_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_1_METHOD + severity: WARNING +- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run + languages: + - python + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if + external data can reach this function call because it allows a malicious actor to run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27267 + rule_id: KxUKzx + rv_id: 1263521 + url: + https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + version_id: l4TJRgo + shortlink: https://sg.run/9pRY + source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$X = code.InteractiveConsole(...)\n...\n" + - pattern-inside: "$X = code.InteractiveInterpreter(...)\n...\n" + - pattern-either: + - pattern: "$X.push($PAYLOAD,...)\n" + - pattern: "$X.runsource($PAYLOAD,...)\n" + - pattern: "$X.runcode(code.compile_command($PAYLOAD),...)\n" + - pattern: "$PL = code.compile_command($PAYLOAD,...)\n...\n$X.runcode($PL,...)\n" + - focus-metavariable: $PAYLOAD + - pattern-not: "$X.push(\"...\",...)\n" + - pattern-not: "$X.runsource(\"...\",...)\n" + - pattern-not: "$X.runcode(code.compile_command(\"...\"),...)\n" + - pattern-not: "$PL = code.compile_command(\"...\",...)\n...\n$X.runcode($PL,...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- id: python.lang.security.dangerous-os-exec.dangerous-os-exec + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27268 + rule_id: qNUR13 + rv_id: 1263523 + url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec + version_id: 6xT29rz + shortlink: https://sg.run/yL9x + source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27269 + rule_id: lBUJrn + rv_id: 1263524 + url: + https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + version_id: o5TbDO5 + shortlink: https://sg.run/r8Zn + source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + - patterns: + - pattern-either: + - pattern: os.environ['$ANYTHING'] + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb['$ANYTHING'] + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv[...] + - pattern: sys.orig_argv[...] + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + languages: + - python + message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run + arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27270 + rule_id: PeURWr + rv_id: 1263525 + url: + https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + version_id: zyTb2OX + shortlink: https://sg.run/bPop + source: + https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern: "_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)\n" + - pattern-not: "_xxsubinterpreters.run_string($ID, \"...\", ...)\n" + - focus-metavariable: $PAYLOAD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + languages: + - python + message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to + perform command injection. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27271 + rule_id: JDUz3R + rv_id: 1263526 + url: + https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + version_id: pZT038J + shortlink: https://sg.run/NWxp + source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-system-call.dangerous-system-call + languages: + - python + message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use + the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection + vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27272 + rule_id: 5rUoP1 + rv_id: 1263527 + url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call + version_id: 2KTv2Zn + shortlink: https://sg.run/k0W7 + source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: getattr(os, "system")(...) + - pattern: __import__("os").system(...) + - pattern: getattr(__import__("os"), "system")(...) + - pattern: "$X = __import__(\"os\")\n...\n$X.system(...)\n" + - pattern: "$X = __import__(\"os\")\n...\ngetattr($X, \"system\")(...)\n" + - pattern: "$X = getattr(os, \"system\")\n...\n$X(...)\n" + - pattern: "$X = __import__(\"os\")\n...\n$Y = getattr($X, \"system\")\n...\n$Y(...)\n" + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + languages: + - python + message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to + run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27273 + rule_id: GdUkxR + rv_id: 1263528 + url: + https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + version_id: X0Tzy1e + shortlink: https://sg.run/wLpY + source: + https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "_testcapi.run_in_subinterp($PAYLOAD, ...)\n" + - pattern: "test.support.run_in_subinterp($PAYLOAD, ...)\n" + - focus-metavariable: $PAYLOAD + - pattern-not: "_testcapi.run_in_subinterp(\"...\", ...)\n" + - pattern-not: "test.support.run_in_subinterp(\"...\", ...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- fix-regex: + count: 1 + regex: unsafe_load + replacement: safe_load + id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + languages: + - python + message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, + and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the + YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow + the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` + or `yaml.SafeLoader` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation + - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 + semgrep.dev: + rule: + origin: community + r_id: 9673 + rule_id: ZqU5jZ + rv_id: 1263530 + url: + https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + version_id: 1QTyprw + shortlink: https://sg.run/we9Y + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + subcategory: + - audit + technology: + - pyyaml + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "import yaml\n...\n" + - pattern-not-inside: "$YAML = ruamel.yaml.YAML(...)\n...\n" + - pattern-either: + - pattern: yaml.unsafe_load(...) + - pattern: yaml.load(..., Loader=yaml.Loader, ...) + - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load(..., Loader=yaml.CLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) + - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) + severity: ERROR +- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + languages: + - python + message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create arbitrary Python objects. A malicious + actor could exploit this to run arbitrary code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ + semgrep.dev: + rule: + origin: community + r_id: 9674 + rule_id: nJUzqK + rv_id: 1263531 + url: + https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + version_id: 9lT4bvG + shortlink: https://sg.run/x1rz + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + subcategory: + - audit + technology: + - ruamel.yaml + vulnerability_class: + - 'Insecure Deserialization ' + pattern-either: + - pattern: ruamel.yaml.YAML(..., typ='unsafe', ...) + - pattern: ruamel.yaml.YAML(..., typ='base', ...) + severity: ERROR +- id: python.lang.security.deserialization.pickle.avoid-shelve + languages: + - python + message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code execution vulnerabilities. When + unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the + relevant data as JSON or a similar text-based serialization format. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + semgrep.dev: + rule: + origin: community + r_id: 9678 + rule_id: 8GUje2 + rv_id: 1263535 + url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve + version_id: NdTzyb4 + shortlink: https://sg.run/dKkZ + source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve + subcategory: + - audit + technology: + - python + vulnerability_class: + - 'Insecure Deserialization ' + pattern: shelve.$FUNC(...) + severity: WARNING +- id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33633 + rule_id: PeU2e2 + rv_id: 1263536 + url: + https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + version_id: kbTzGE1 + shortlink: https://sg.run/vYrY + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: hashlib.md5(...) + - pattern-not: hashlib.md5(..., usedforsecurity=False, ...) + severity: WARNING +- fix-regex: + regex: sha1 + replacement: sha256 + id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9624 + rule_id: x8UnBk + rv_id: 1263537 + url: + https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + version_id: w8TRoE7 + shortlink: https://sg.run/ydYx + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern: hashlib.sha1(...) + severity: WARNING +- id: python.lang.security.insecure-hash-function.insecure-hash-function + languages: + - python + message: Detected use of an insecure MD4 or MD5 hash function. These functions have known vulnerabilities and are + considered deprecated. Consider using 'SHA256' or a similar function instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9625 + rule_id: OrU30g + rv_id: 1501841 + url: https://semgrep.dev/playground/r/xyT0gk7/python.lang.security.insecure-hash-function.insecure-hash-function + version_id: xyT0gk7 + shortlink: https://sg.run/rdBn + source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...) + - pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...) + - pattern-not: hashlib.new(..., usedforsecurity=False, ...) + severity: WARNING +- fix-regex: + regex: uuid1 + replacement: uuid4 + id: python.lang.security.insecure-uuid-version.insecure-uuid-version + languages: + - python + message: Using UUID version 1 for UUID generation can lead to predictable UUIDs based on system information (e.g., MAC + address, timestamp). This may lead to security risks such as the sandwich attack. Consider using `uuid.uuid4()` + instead for better randomness and security. + metadata: + asvs: + control_id: 6.3.2 Insecure UUID Generation + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.landh.tech/blog/20230811-sandwich-attack/ + semgrep.dev: + rule: + origin: community + r_id: 148295 + rule_id: kxUd1yD + rv_id: 1263539 + url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version + version_id: O9Tpx97 + shortlink: https://sg.run/BYBgW + source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: uuid.uuid1(...) + severity: WARNING +- fix-regex: + regex: _create_unverified_context + replacement: create_default_context + id: python.lang.security.unverified-ssl-context.unverified-ssl-context + languages: + - python + message: Unverified SSL context detected. This will permit insecure connections without verifying SSL certificates. + Use 'ssl.create_default_context' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.python.org/3/library/ssl.html#ssl-security + - https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection + semgrep.dev: + rule: + origin: community + r_id: 9627 + rule_id: v8UnkQ + rv_id: 1263540 + url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context + version_id: e1Tyjlj + shortlink: https://sg.run/N4lp + source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context + subcategory: + - audit + technology: + - python + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: ssl._create_unverified_context(...) + - pattern: ssl._create_default_https_context = ssl._create_unverified_context + severity: ERROR +- fix: defusedxml.etree.ElementTree.parse($...ARGS) + id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse + languages: + - python + message: The native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak + confidential data and "XML bombs" can cause denial of service. Do not use this library to parse untrusted input. + Instead the Python documentation recommends using `defusedxml`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://docs.python.org/3/library/xml.html + - https://github.com/tiran/defusedxml + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + semgrep.dev: + rule: + origin: community + r_id: 72436 + rule_id: X5Uqnx + rv_id: 1263541 + url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + version_id: vdT06ER + shortlink: https://sg.run/n3jG + source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + subcategory: + - vuln + technology: + - python + vulnerability_class: + - XML Injection + patterns: + - pattern: xml.etree.ElementTree.parse($...ARGS) + - pattern-not: xml.etree.ElementTree.parse("...") + severity: ERROR +- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + languages: + - python + message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm is not cryptographically + secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block + cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that + also provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33634 + rule_id: JDUGnK + rv_id: 1263545 + url: + https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + version_id: ExTExln + shortlink: https://sg.run/dlOE + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.Blowfish.new(...) + - pattern: Crypto.Cipher.Blowfish.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + languages: + - python + message: Detected DES cipher or Triple DES algorithm which is considered insecure. This algorithm is not + cryptographically secure and can be reversed easily. Use a secure symmetric cipher from the cryptodome package + instead. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a + block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, + such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33635 + rule_id: 5rUr73 + rv_id: 1263546 + url: + https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + version_id: 7ZTE3G7 + shortlink: https://sg.run/Z5bw + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.DES.new(...) + - pattern: Crypto.Cipher.DES.new(...) + - pattern: Cryptodome.Cipher.DES3.new(...) + - pattern: Crypto.Cipher.DES3.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + languages: + - python + message: Detected RC2 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher + such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also + provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33636 + rule_id: GdUYlW + rv_id: 1263547 + url: + https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + version_id: LjTkgn6 + shortlink: https://sg.run/nAbY + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.ARC2.new(...) + - pattern: Crypto.Cipher.ARC2.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + languages: + - python + message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher + such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also + provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33637 + rule_id: ReUnEB + rv_id: 1263548 + url: + https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + version_id: 8KT5rXY + shortlink: https://sg.run/Eo6N + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Cryptodome.Cipher.ARC4.new(...) + - pattern: Crypto.Cipher.ARC4.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + languages: + - python + message: Detected XOR cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use AES instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + semgrep.dev: + rule: + origin: community + r_id: 9683 + rule_id: PeUk5W + rv_id: 1263549 + url: + https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + version_id: gETB7j3 + shortlink: https://sg.run/L0yr + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Cryptodome.Cipher.XOR.new(...) + - pattern: Crypto.Cipher.XOR.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + languages: + - python + message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33638 + rule_id: AbU0Ex + rv_id: 1263550 + url: + https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + version_id: QkTGqD8 + shortlink: https://sg.run/7JP2 + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD2.new(...) + - pattern: Cryptodome.Hash.MD2.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + languages: + - python + message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33639 + rule_id: BYUJy4 + rv_id: 1263551 + url: + https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + version_id: 3ZT4Xnp + shortlink: https://sg.run/Lve6 + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD4.new(...) + - pattern: Cryptodome.Hash.MD4.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33640 + rule_id: DbUXwo + rv_id: 1263552 + url: + https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + version_id: 44TEjpk + shortlink: https://sg.run/85JN + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD5.new(...) + - pattern: Cryptodome.Hash.MD5.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9687 + rule_id: ReUPO3 + rv_id: 1263553 + url: + https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + version_id: PkTR3vk + shortlink: https://sg.run/3ALr + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Crypto.Hash.SHA.new(...) + - pattern: Cryptodome.Hash.SHA.new (...) + severity: WARNING +- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + languages: + - python + message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/public_key/dsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + semgrep.dev: + rule: + origin: community + r_id: 9688 + rule_id: AbUWje + rv_id: 1263554 + url: + https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + version_id: JdTzxbQ + shortlink: https://sg.run/4y8l + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.DSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + severity: WARNING +- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + languages: + - python + message: Detected an insufficient key size for RSA. NIST recommends a key size of 3072 or higher. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/public_key/rsa#rsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + semgrep.dev: + rule: + origin: community + r_id: 9689 + rule_id: BYUBWe + rv_id: 1263555 + url: + https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + version_id: 5PTo1jL + shortlink: https://sg.run/PprY + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.RSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 3072 + metavariable: $SIZE + severity: WARNING +- id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + languages: + - python + message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result + in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 31872 + rule_id: YGUw8w + rv_id: 1263556 + url: + https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + version_id: GxTkeyz + shortlink: https://sg.run/k1K1 + source: + https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "AES.new(..., $PYCRYPTODOME_MODE)\n" + - pattern-not-inside: "AES.new(..., $PYCRYPTODOME_MODE)\n...\nHMAC.new\n" + - metavariable-pattern: + metavariable: $PYCRYPTODOME_MODE + patterns: + - pattern-either: + - pattern: AES.MODE_CBC + - pattern: AES.MODE_CTR + - pattern: AES.MODE_CFB + - pattern: AES.MODE_OFB + severity: ERROR +- fix: "$...PARAMS, httponly=True\n" + id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies + should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21437 + rule_id: bwUXKB + rv_id: 1263557 + url: + https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + version_id: RGT0L7K + shortlink: https://sg.run/EprB + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern: pyramid.authentication.$FUNC($...PARAMS) + - metavariable-pattern: + metavariable: $FUNC + pattern-either: + - pattern: AuthTktCookieHelper + - pattern: AuthTktAuthenticationPolicy + - pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...) + - pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...) + - focus-metavariable: $...PARAMS + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies + should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21438 + rule_id: NbUq9e + rv_id: 1263558 + url: + https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + version_id: A8Tgd8N + shortlink: https://sg.run/7DgQ + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY, ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY, ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: "False\n" + severity: WARNING +- fix: "'Lax'\n" + id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + languages: + - python + message: Found a Pyramid Authentication Ticket without the samesite option correctly set. Pyramid cookies should be + handled securely by setting samesite='Lax'. If this parameter is not properly set, your cookies are not properly + protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21439 + rule_id: kxUYjY + rv_id: 1263559 + url: + https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + version_id: BjTkZ51 + shortlink: https://sg.run/LYrY + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE, ...) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE, ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + languages: + - python + message: Found a Pyramid Authentication Ticket cookie using an unsafe default for the secure option. Pyramid cookies + should be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21440 + rule_id: wdUKzn + rv_id: 1263560 + url: + https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + version_id: DkTRbJn + shortlink: https://sg.run/8WxQ + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the secure option correctly set. Pyramid cookies should + be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not properly + protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21441 + rule_id: x8UqAp + rv_id: 1263561 + url: + https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + version_id: WrTqK93 + shortlink: https://sg.run/gjp5 + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: "False\n" + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + languages: + - python + message: Automatic check of the referrer for cross-site request forgery tokens has been explicitly disabled globally, + which might leave views unprotected when an unsafe CSRF storage policy is used. Use + 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)' to turn the automatic check for all unsafe + methods (per RFC2616). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21443 + rule_id: eqU9Le + rv_id: 1263563 + url: + https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + version_id: K3TKkeo + shortlink: https://sg.run/3GeW + source: + https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "$CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...)\n" + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + comparison: $CHECK_ORIGIN == False + metavariable: $CHECK_ORIGIN + severity: ERROR +- fix: "True\n" + id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + languages: + - python + message: Origin check for the CSRF token is disabled for this view. This might represent a security risk if the CSRF + storage policy is not known to be secure. + metadata: + asvs: + control_id: 4.2.2 CSRF + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + section: V4 Access Control + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21444 + rule_id: v8UGpL + rv_id: 1263564 + url: + https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + version_id: qkTR7Gv + shortlink: https://sg.run/4RB9 + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "from pyramid.view import view_config\n...\n@view_config(..., check_origin=$CHECK_ORIGIN, ...)\ndef $VIEW(...):\n\ + \ ...\n" + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + comparison: $CHECK_ORIGIN == False + metavariable: $CHECK_ORIGIN + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, httponly=True) + id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe default for the httponly option. Pyramid cookies should be handled + securely by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies + are not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21445 + rule_id: d8UPQ7 + rv_id: 1263565 + url: + https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + version_id: l4TJRbo + shortlink: https://sg.run/P19v + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the httponly option correctly set. Pyramid cookies should be handled securely + by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/www-community/controls/SecureCookieAttribute + - https://owasp.org/www-community/HttpOnly + - https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute + semgrep.dev: + rule: + origin: community + r_id: 21446 + rule_id: ZqU37W + rv_id: 1263566 + url: + https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + version_id: YDTZe54 + shortlink: https://sg.run/JbqP + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: "False\n" + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, samesite='Lax') + id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid cookies should be handled + securely by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies + are not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21447 + rule_id: nJUp80 + rv_id: 1263567 + url: + https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + version_id: 6xT293z + shortlink: https://sg.run/5AWj + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "'Lax'\n" + id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the samesite option correctly set. Pyramid cookies should be handled securely + by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21448 + rule_id: EwUgpY + rv_id: 1263568 + url: + https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + version_id: o5TbDv5 + shortlink: https://sg.run/GXR6 + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid cookies should be handled + securely by setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are + not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21449 + rule_id: 7KUr15 + rv_id: 1263569 + url: + https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + version_id: zyTb2dX + shortlink: https://sg.run/RbrN + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the secure option correctly set. Pyramid cookies should be handled securely by + setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21450 + rule_id: L1UX2J + rv_id: 1263570 + url: + https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + version_id: pZT03oJ + shortlink: https://sg.run/AzjB + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: "False\n" + severity: WARNING +- fix: "True\n" + id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + languages: + - python + message: Automatic check of cross-site request forgery tokens has been explicitly disabled globally, which might leave + views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)' to turn the + automatic check for all unsafe methods (per RFC2616). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21451 + rule_id: 8GUKqP + rv_id: 1263571 + url: + https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + version_id: 2KTv2en + shortlink: https://sg.run/Bx2R + source: + https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "$CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...)\n" + - pattern: $REQUIRE_CSRF + - metavariable-comparison: + comparison: $REQUIRE_CSRF == False + metavariable: $REQUIRE_CSRF + severity: ERROR +- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + languages: + - python + message: Detected data rendered directly to the end user via 'Response'. This bypasses Pyramid's built-in cross-site + scripting (XSS) defenses and could result in an XSS vulnerability. Use Pyramid's template engines to safely render + HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 21452 + rule_id: gxUeA8 + rv_id: 1263572 + url: + https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + version_id: X0TzyEe + shortlink: https://sg.run/DX8G + source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "pyramid.request.Response.text($SINK)\n" + - pattern: "pyramid.request.Response($SINK)\n" + - pattern: "$REQ.response.body = $SINK\n" + - pattern: "$REQ.response.text = $SINK\n" + - pattern: "$REQ.response.ubody = $SINK\n" + - pattern: "$REQ.response.unicode_body = $SINK\n" + - pattern: $SINK + pattern-sources: + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- fix-regex: + regex: format + replacement: bindparams + id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + languages: + - python + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer + inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs + raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with + any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data + semgrep.dev: + rule: + origin: community + r_id: 21453 + rule_id: QrUZ7l + rv_id: 1263573 + url: + https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + version_id: jQTn5WA + shortlink: https://sg.run/W7eE + source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$QUERY = $REQ.dbsession.query(...)\n...\n" + - pattern-either: + - pattern: "$QUERY.$SQLFUNC(\"...\".$FORMATFUNC(..., $SINK, ...))\n" + - pattern: "$QUERY.join(...).$SQLFUNC(\"...\".$FORMATFUNC(..., $SINK, ...))\n" + - pattern: $SINK + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + pattern-sources: + - patterns: + - pattern-inside: "from pyramid.view import view_config\n...\n@view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + languages: + - python + message: sqlalchemy.text passes the constructed SQL statement to the database mostly unchanged. This means that the + usual SQL injection protections are not applied and this function is vulnerable to SQL injection if user input can + reach here. Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct SQL. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + semgrep.dev: + rule: + origin: community + r_id: 15824 + rule_id: r6U2wE + rv_id: 1263577 + url: + https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + version_id: rxTAKqq + shortlink: https://sg.run/yP1O + source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + subcategory: + - audit + technology: + - sqlalchemy + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - pattern: "sqlalchemy.text(...)\n" + pattern-sources: + - patterns: + - pattern: "$X + $Y\n" + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: "$X + $Y\n" + - metavariable-type: + metavariable: $Y + type: string + - patterns: + - pattern: "f\"...\"\n" + - patterns: + - pattern: "$X.format(...)\n" + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: "$X % $Y\n" + - metavariable-type: + metavariable: $X + type: string + severity: ERROR +- fix-regex: + regex: format + replacement: bindparams + id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + languages: + - python + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer + inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs + raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with + any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9702 + rule_id: BYUBWo + rv_id: 1263579 + url: + https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + version_id: NdTzyL4 + shortlink: https://sg.run/J3Xo + source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + subcategory: + - vuln + technology: + - sqlalchemy + vulnerability_class: + - SQL Injection + patterns: + - pattern-either: + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query(...).$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query.join(...).$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query.$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n query.$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + severity: WARNING +- id: python.twilio.security.twiml-injection.twiml-injection + languages: + - python + message: Using non-constant TwiML (Twilio Markup Language) argument when creating a Twilio conversation could allow + the injection of additional TwiML commands + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-91: XML Injection' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://codeberg.org/fennix/funjection + semgrep.dev: + rule: + origin: community + r_id: 134692 + rule_id: oqUgjj2 + rv_id: 1263580 + url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection + version_id: kbTzGp1 + shortlink: https://sg.run/GdEEy + source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection + subcategory: + - vuln + technology: + - python + - twilio + - twiml + vulnerability_class: + - Other + mode: taint + pattern-sanitizers: + - pattern: xml.sax.saxutils.escape(...) + - pattern: html.escape(...) + pattern-sinks: + - patterns: + - pattern: "$CLIENT.calls.create(..., twiml=$SINK, ...)\n" + - focus-metavariable: $SINK + pattern-sources: + - pattern: "f\"...\"\n" + - pattern: "\"...\" % ...\n" + - pattern: "\"...\".format(...)\n" + - patterns: + - pattern: $ARG + - pattern-inside: "def $F(..., $ARG, ...):\n ...\n" + severity: WARNING +- id: ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `Example.find_by_sql ["SELECT title FROM posts WHERE author = ? + AND created > ?", author_id, start_date]`' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://guides.rubyonrails.org/active_record_querying.html#finding-by-sql + semgrep.dev: + rule: + origin: community + r_id: 18277 + rule_id: 0oUw9g + rv_id: 1263581 + url: https://semgrep.dev/playground/r/w8TRor7/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + version_id: w8TRor7 + shortlink: https://sg.run/vXvY + source: https://semgrep.dev/r/ruby.aws-lambda.security.activerecord-sqli.activerecord-sqli + subcategory: + - vuln + technology: + - aws-lambda + - active-record + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: ActiveRecord::Base.connection.execute($QUERY,...) + - pattern: $MODEL.find_by_sql($QUERY,...) + - pattern: $MODEL.select_all($QUERY,...) + - pattern-inside: "require 'active_record'\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: WARNING +- id: ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + languages: + - ruby + message: 'Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use sanitize statements like so: `escaped = client.escape(user_input)`' + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/brianmario/mysql2 + semgrep.dev: + rule: + origin: community + r_id: 18278 + rule_id: KxUrQ3 + rv_id: 1263582 + url: https://semgrep.dev/playground/r/xyTjzOe/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + version_id: xyTjzOe + shortlink: https://sg.run/dJLE + source: https://semgrep.dev/r/ruby.aws-lambda.security.mysql2-sqli.mysql2-sqli + subcategory: + - vuln + technology: + - aws-lambda + - mysql2 + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - pattern: $CLIENT.escape(...) + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CLIENT.query($QUERY,...) + - pattern: $CLIENT.prepare($QUERY,...) + - pattern-inside: "require 'mysql2'\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: WARNING +- id: ruby.aws-lambda.security.pg-sqli.pg-sqli + languages: + - ruby + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `conn.exec_params('SELECT $1 AS a, $2 AS b, $3 AS c', [1, 2, nil])`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + semgrep.dev: + rule: + origin: community + r_id: 18279 + rule_id: qNUQee + rv_id: 1263583 + url: https://semgrep.dev/playground/r/O9Tpxz7/ruby.aws-lambda.security.pg-sqli.pg-sqli + version_id: O9Tpxz7 + shortlink: https://sg.run/ZKww + source: https://semgrep.dev/r/ruby.aws-lambda.security.pg-sqli.pg-sqli + subcategory: + - vuln + technology: + - aws-lambda + - postgres + - pg + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: $CONN.exec($QUERY,...) + - pattern: $CONN.exec_params($QUERY,...) + - pattern: $CONN.exec_prepared($QUERY,...) + - pattern: $CONN.async_exec($QUERY,...) + - pattern: $CONN.async_exec_params($QUERY,...) + - pattern: $CONN.async_exec_prepared($QUERY,...) + - pattern-inside: "require 'pg'\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: WARNING +- id: ruby.aws-lambda.security.sequel-sqli.sequel-sqli + languages: + - ruby + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `DB['select * from items where name = ?', name]`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/jeremyevans/sequel#label-Arbitrary+SQL+queries + semgrep.dev: + rule: + origin: community + r_id: 18280 + rule_id: lBUy2N + rv_id: 1263584 + url: https://semgrep.dev/playground/r/e1Tyj5j/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + version_id: e1Tyj5j + shortlink: https://sg.run/n9vY + source: https://semgrep.dev/r/ruby.aws-lambda.security.sequel-sqli.sequel-sqli + subcategory: + - vuln + technology: + - aws-lambda + - sequel + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $QUERY + - pattern-either: + - pattern: DB[$QUERY,...] + - pattern: DB.run($QUERY,...) + - pattern-inside: "require 'sequel'\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: WARNING +- id: ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + languages: + - ruby + message: Deserialization of a string tainted by `event` object found. Objects in Ruby can be serialized into strings, + then later loaded from strings. However, uses of `load` can cause remote code execution. Loading user input with + MARSHAL, YAML or CSV can potentially be dangerous. If you need to deserialize untrusted data, you should use JSON as + it is only capable of returning 'primitive' types such as strings, arrays, hashes, numbers and nil. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://ruby-doc.org/core-3.1.2/doc/security_rdoc.html + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + semgrep.dev: + rule: + origin: community + r_id: 22078 + rule_id: zdUlNJ + rv_id: 1263585 + url: + https://semgrep.dev/playground/r/vdT06gR/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + version_id: vdT06gR + shortlink: https://sg.run/dplX + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-deserialization.tainted-deserialization + subcategory: + - vuln + technology: + - ruby + - aws-lambda + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - patterns: + - pattern: $SINK + - pattern-either: + - pattern-inside: "YAML.load($SINK,...)\n" + - pattern-inside: "CSV.load($SINK,...)\n" + - pattern-inside: "Marshal.load($SINK,...)\n" + - pattern-inside: "Marshal.restore($SINK,...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: WARNING +- id: ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - ruby + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://rorsecurity.info/portfolio/ruby-on-rails-sql-injection-cheat-sheet + semgrep.dev: + rule: + origin: community + r_id: 18281 + rule_id: PeUxOE + rv_id: 1263586 + url: https://semgrep.dev/playground/r/d6Tyx1Z/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: d6Tyx1Z + shortlink: https://sg.run/EB7N + source: https://semgrep.dev/r/ruby.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: "\"...#{...}...\"\n" + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", ...) + - pattern: "\"$SQLSTR\" + $EXPR\n" + - pattern: "\"$SQLSTR\" % $EXPR\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b|\w+\s*!?[<>=].* + - pattern-not-inside: "puts(...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context)\n ...\nend\n" + severity: ERROR +- id: ruby.lang.security.audit.sha224-hash.sha224-hash + languages: + - ruby + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-328: Use of Weak Hash' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151753 + rule_id: DbU60wQ + rv_id: 1263592 + url: https://semgrep.dev/playground/r/8KT5rRY/ruby.lang.security.audit.sha224-hash.sha224-hash + version_id: 8KT5rRY + shortlink: https://sg.run/WABbo + source: https://semgrep.dev/r/ruby.lang.security.audit.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: Digest::SHA224.$FUNC + - pattern: OpenSSL::Digest::SHA224.$FUNC + - pattern: SHA3::Digest::SHA224(...) + - patterns: + - pattern-either: + - pattern: OpenSSL::HMAC.hexdigest("$ALGO", ...) + - pattern: OpenSSL::HMAC.digest("$ALGO", ...) + - pattern: OpenSSL::HMAC.new($KEY, "$ALGO") + - pattern: OpenSSL::Digest.digest("$ALGO", ...) + - pattern: OpenSSL::Digest.new("$ALGO", ...) + - metavariable-regex: + metavariable: $ALGO + regex: .*224 + severity: WARNING +- id: ruby.lang.security.bad-deserialization.bad-deserialization + languages: + - ruby + message: Checks for unsafe deserialization. Objects in Ruby can be serialized into strings, then later loaded from + strings. However, uses of load and object_load can cause remote code execution. Loading user input with MARSHAL or + CSV can potentially be dangerous. Use JSON in a secure fashion instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://groups.google.com/g/rubyonrails-security/c/61bkgvnSGTQ/m/nehwjA8tQ8EJ + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_deserialize.rb + semgrep.dev: + rule: + origin: community + r_id: 9708 + rule_id: lBUdQg + rv_id: 1263595 + url: https://semgrep.dev/playground/r/3ZT4Xqp/ruby.lang.security.bad-deserialization.bad-deserialization + version_id: 3ZT4Xqp + shortlink: https://sg.run/DJj2 + source: https://semgrep.dev/r/ruby.lang.security.bad-deserialization.bad-deserialization + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - pattern-either: + - pattern: "CSV.load(...)\n" + - pattern: "Marshal.load(...)\n" + - pattern: "Marshal.restore(...)\n" + - pattern: "Oj.object_load(...)\n" + - pattern: "Oj.load($X)\n" + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + severity: ERROR +- id: ruby.lang.security.dangerous-exec.dangerous-exec + languages: + - ruby + message: Detected non-static command inside $EXEC. Audit the input to '$EXEC'. If unverified user data can reach this + call site, this is a code injection vulnerability. A malicious actor can inject a malicious script to execute + arbitrary code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://guides.rubyonrails.org/security.html#command-line-injection + semgrep.dev: + rule: + origin: community + r_id: 9805 + rule_id: WAUZOw + rv_id: 1409405 + url: https://semgrep.dev/playground/r/WrT7erb/ruby.lang.security.dangerous-exec.dangerous-exec + version_id: WrT7erb + shortlink: https://sg.run/R8GY + source: https://semgrep.dev/r/ruby.lang.security.dangerous-exec.dangerous-exec + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_execute.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: "$EXEC(...)\n" + - pattern-not: "$EXEC(\"...\",\"...\",\"...\",...)\n" + - pattern-not: "$EXEC([\"...\",\"...\",\"...\",...],...)\n" + - pattern-not: "$EXEC({...},\"...\",\"...\",\"...\",...)\n" + - pattern-not: "$EXEC({...},[\"...\",\"...\",\"...\",...],...)\n" + - metavariable-regex: + metavariable: $EXEC + regex: + ^(system|exec|spawn|Process.exec|Process.spawn|Open3.capture2|Open3.capture2e|Open3.capture3|Open3.popen2|Open3.popen2e|Open3.popen3|IO.popen|Gem::Util.popen|PTY.spawn)$ + pattern-sources: + - patterns: + - pattern: "def $F(...,$ARG,...)\n ...\nend\n" + - focus-metavariable: $ARG + - pattern: params + - pattern: cookies + severity: WARNING +- fix-regex: + regex: =\s*false + replacement: = true + id: ruby.lang.security.force-ssl-false.force-ssl-false + languages: + - ruby + message: Checks for configuration setting of force_ssl to false. Force_ssl forces usage of HTTPS, which could lead to + network interception of unencrypted application traffic. To fix, set config.force_ssl = true. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_force_ssl.rb + semgrep.dev: + rule: + origin: community + r_id: 9714 + rule_id: 2ZU4lx + rv_id: 1263605 + url: https://semgrep.dev/playground/r/WrTqKB3/ruby.lang.security.force-ssl-false.force-ssl-false + version_id: WrTqKB3 + shortlink: https://sg.run/YgkW + source: https://semgrep.dev/r/ruby.lang.security.force-ssl-false.force-ssl-false + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Cryptographic Issues + pattern: config.force_ssl = false + severity: WARNING +- id: ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + languages: + - ruby + message: Detected hardcoded password used in basic authentication in a controller class. Including this password in + version control could expose this credential. Consider refactoring to use environment variables or configuration + files. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9715 + rule_id: X5UZWK + rv_id: 1263606 + url: + https://semgrep.dev/playground/r/0bTKzNK/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + version_id: 0bTKzNK + shortlink: https://sg.run/6r0w + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-http-auth-in-controller.hardcoded-http-auth-in-controller + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/basic_auth/index.markdown + subcategory: + - audit + technology: + - ruby + - secrets + vulnerability_class: + - Hard-coded Secrets + patterns: + - pattern-inside: "class $CONTROLLER < ApplicationController\n ...\n http_basic_authenticate_with ..., :password => \"\ + $SECRET\", ...\nend\n" + - focus-metavariable: $SECRET + severity: WARNING +- id: ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + languages: + - ruby + message: Found the use of an hardcoded passphrase for RSA. The passphrase can be easily discovered, and therefore + should not be stored in source-code. It is recommended to remove the passphrase from source-code, and use system + environment variables or a restricted configuration file. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cwe.mitre.org/data/definitions/522.html + semgrep.dev: + rule: + origin: community + r_id: 20730 + rule_id: bwULyN + rv_id: 1263607 + url: + https://semgrep.dev/playground/r/K3TKkEo/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + version_id: K3TKkEo + shortlink: https://sg.run/xPEe + source: https://semgrep.dev/r/ruby.lang.security.hardcoded-secret-rsa-passphrase.hardcoded-secret-rsa-passphrase + subcategory: + - vuln + technology: + - ruby + - secrets + vulnerability_class: + - Hard-coded Secrets + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).to_pem(..., '...') + - pattern: OpenSSL::PKey::RSA.new(...).export(..., '...') + - patterns: + - pattern-inside: "$OPENSSL = OpenSSL::PKey::RSA.new(...)\n...\n" + - pattern-either: + - pattern: "$OPENSSL.export(...,'...')\n" + - pattern: "$OPENSSL.to_pem(...,'...')\n" + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$ASSIGN = '...'\n...\n" + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: "def $METHOD1(...)\n...\n$ASSIGN = '...'\n...\nend\n...\ndef $METHOD2(...)\n...\nend\n" + - pattern: OpenSSL::PKey::RSA.new(..., $ASSIGN) + - patterns: + - pattern-inside: "$ASSIGN = '...'\n...\ndef $METHOD(...)\n $OPENSSL = OpenSSL::PKey::RSA.new(...)\n...\nend\n\ + ...\n" + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: "def $METHOD1(...)\n...\n$OPENSSL = OpenSSL::PKey::RSA.new(...)\n...\n$ASSIGN = '...'\n...\nend\n\ + ...\n" + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + - patterns: + - pattern-inside: "def $METHOD1(...)\n...\n$ASSIGN = '...'\n...\nend\n...\ndef $METHOD2(...)\n...\n$OPENSSL = OpenSSL::PKey::RSA.new(...)\n\ + ...\nend\n...\n" + - pattern-either: + - pattern: $OPENSSL.export(...,$ASSIGN) + - pattern: $OPENSSL.to_pem(...,$ASSIGN) + severity: WARNING +- id: ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + languages: + - ruby + message: The RSA key size $SIZE is insufficent by NIST standards. It is recommended to use a key length of 2048 or + higher. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + semgrep.dev: + rule: + origin: community + r_id: 20731 + rule_id: NbUe4N + rv_id: 1263608 + url: + https://semgrep.dev/playground/r/qkTR76v/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + version_id: qkTR76v + shortlink: https://sg.run/O4Re + source: https://semgrep.dev/r/ruby.lang.security.insufficient-rsa-key-size.insufficient-rsa-key-size + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: OpenSSL::PKey::RSA.generate($SIZE,...) + - pattern: OpenSSL::PKey::RSA.new($SIZE, ...) + - patterns: + - pattern-either: + - patterns: + - pattern-inside: "$ASSIGN = $SIZE\n...\n" + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - patterns: + - pattern-inside: "def $METHOD1(...)\n...\n$ASSIGN = $SIZE\n...\nend\n...\n" + - pattern-either: + - pattern: OpenSSL::PKey::RSA.new($ASSIGN, ...) + - pattern: OpenSSL::PKey::RSA.generate($ASSIGN, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + severity: WARNING +- id: ruby.lang.security.md5-used-as-password.md5-used-as-password + languages: + - ruby + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Instead, use a suitable password hashing function such as bcrypt. + You can use the `bcrypt` gem. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/id/draft-lvelvindron-tls-md5-sha1-deprecate-01.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + semgrep.dev: + rule: + origin: community + r_id: 14704 + rule_id: oqU4p2 + rv_id: 1263611 + url: https://semgrep.dev/playground/r/JdTzx0e/ruby.lang.security.md5-used-as-password.md5-used-as-password + version_id: JdTzx0e + shortlink: https://sg.run/GOZy + source: https://semgrep.dev/r/ruby.lang.security.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...); + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - pattern: Digest::MD5 + severity: WARNING +- id: ruby.lang.security.no-eval.ruby-eval + languages: + - ruby + message: Use of eval with user-controllable input detected. This can lead to attackers running arbitrary code. Ensure + external data does not reach here, otherwise this is a security vulnerability. Consider other ways to do this + without eval. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9726 + rule_id: OrUGNk + rv_id: 1263615 + url: https://semgrep.dev/playground/r/A8TgdDv/ruby.lang.security.no-eval.ruby-eval + version_id: A8TgdDv + shortlink: https://sg.run/bDwZ + source: https://semgrep.dev/r/ruby.lang.security.no-eval.ruby-eval + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_evaluation.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.eval + - pattern: $X.class_eval + - pattern: $X.instance_eval + - pattern: $X.module_eval + - pattern: $X.eval(...) + - pattern: $X.class_eval(...) + - pattern: $X.instance_eval(...) + - pattern: $X.module_eval(...) + - pattern: eval(...) + - pattern: class_eval(...) + - pattern: module_eval(...) + - pattern: instance_eval(...) + - pattern-not: $M("...",...) + pattern-sources: + - pattern-either: + - pattern: params + - pattern: cookies + - patterns: + - pattern: "RubyVM::InstructionSequence.compile(...)\n" + - pattern-not: "RubyVM::InstructionSequence.compile(\"...\")\n" + severity: WARNING +- fix-regex: + regex: VERIFY_NONE + replacement: VERIFY_PEER + id: ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + languages: + - ruby + message: Detected SSL that will accept an unverified connection. This makes the connections susceptible to + man-in-the-middle attacks. Use 'OpenSSL::SSL::VERIFY_PEER' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 9728 + rule_id: v8U5Yn + rv_id: 1263617 + url: https://semgrep.dev/playground/r/DkTRbl4/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + version_id: DkTRbl4 + shortlink: https://sg.run/kLxX + source: https://semgrep.dev/r/ruby.lang.security.ssl-mode-no-verify.ssl-mode-no-verify + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Improper Authentication + pattern: OpenSSL::SSL::VERIFY_NONE + severity: WARNING +- id: ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + languages: + - ruby + message: Should not use md5 to generate hashes. md5 is proven to be vulnerable through the use of brute-force attacks. + Could also result in collisions, leading to potential collision attacks. Use SHA256 or other hashing functions + instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.ibm.com/support/pages/security-bulletin-vulnerability-md5-signature-and-hash-algorithm-affects-sterling-integrator-and-sterling-file-gateway-cve-2015-7575 + semgrep.dev: + rule: + origin: community + r_id: 9731 + rule_id: nJUYxZ + rv_id: 1263619 + url: https://semgrep.dev/playground/r/0bTKzN8/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + version_id: 0bTKzN8 + shortlink: https://sg.run/O1re + source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-md5.weak-hashes-md5 + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: Digest::MD5.base64digest $X + - pattern: Digest::MD5.hexdigest $X + - pattern: Digest::MD5.digest $X + - pattern: Digest::MD5.new + - pattern: OpenSSL::Digest::MD5.base64digest $X + - pattern: OpenSSL::Digest::MD5.hexdigest $X + - pattern: OpenSSL::Digest::MD5.digest $X + - pattern: OpenSSL::Digest::MD5.new + severity: WARNING +- id: ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + languages: + - ruby + message: Should not use SHA1 to generate hashes. There is a proven SHA1 hash collision by Google, which could lead to + vulnerabilities. Use SHA256, SHA3 or other hashing functions instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html + - https://shattered.io/ + semgrep.dev: + rule: + origin: community + r_id: 9732 + rule_id: EwU4jq + rv_id: 1263620 + url: https://semgrep.dev/playground/r/K3TKkEZ/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + version_id: K3TKkEZ + shortlink: https://sg.run/e4qX + source: https://semgrep.dev/r/ruby.lang.security.weak-hashes-sha1.weak-hashes-sha1 + subcategory: + - vuln + technology: + - ruby + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: Digest::SHA1.$FUNC + - pattern: OpenSSL::Digest::SHA1.$FUNC + - pattern: OpenSSL::HMAC.$FUNC("sha1",...) + severity: WARNING +- id: ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + languages: + - ruby + message: This gets data from session using user inputs. A malicious user may be able to retrieve information from your + session that you didn't intend them to. Do not use user input as a session key. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-276: Incorrect Default Permissions' + cwe2021-top25: true + cwe2022-top25: true + help: "## Remediation\nSession manipulation can occur when an application allows user-input in session keys. Since sessions + are typically considered a source of truth (e.g. to check the logged-in user or to match CSRF tokens), allowing an attacker + to manipulate the session may lead to unintended behavior.\n\n## References\n[Session Manipulation](https://brakemanscanner.org/docs/warning_types/session_manipulation/)\n" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://brakemanscanner.org/docs/warning_types/session_manipulation/ + semgrep.dev: + rule: + origin: community + r_id: 13584 + rule_id: BYUdW6 + rv_id: 1263621 + url: + https://semgrep.dev/playground/r/qkTR76G/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + version_id: qkTR76G + shortDescription: Allowing an attacker to manipulate the session may lead to unintended behavior. + shortlink: https://sg.run/86q7 + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-session-manipulation.avoid-session-manipulation + subcategory: + - vuln + tags: + - security + technology: + - rails + vulnerability_class: + - Improper Authorization + mode: taint + pattern-sinks: + - pattern: session[...] + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + severity: WARNING +- id: ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + languages: + - ruby + message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or + access files they have no right to. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + semgrep.dev: + rule: + origin: community + r_id: 13585 + rule_id: DbU1dr + rv_id: 1263622 + url: + https://semgrep.dev/playground/r/l4TJRkk/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + version_id: l4TJRkk + shortlink: https://sg.run/gYln + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-file-access.avoid-tainted-file-access + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: Dir.$X(...) + - pattern: File.$X(...) + - pattern: IO.$X(...) + - pattern: Kernel.$X(...) + - pattern: PStore.$X(...) + - pattern: Pathname.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: truncate + - pattern: unlink + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + severity: WARNING +- id: ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + languages: + - ruby + message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or + access files they have no right to. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + semgrep.dev: + rule: + origin: community + r_id: 13586 + rule_id: WAUyzp + rv_id: 1263623 + url: + https://semgrep.dev/playground/r/YDTZeWL/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + version_id: YDTZeWL + shortlink: https://sg.run/Q9gP + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-ftp-call.avoid-tainted-ftp-call + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - pattern-either: + - pattern: Net::FTP.$X(...) + - patterns: + - pattern-inside: "$FTP = Net::FTP.$OPEN(...)\n...\n$FTP.$METHOD(...)\n" + - pattern: $FTP.$METHOD(...) + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + severity: WARNING +- id: ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + languages: + - ruby + message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or + access files they have no right to. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + semgrep.dev: + rule: + origin: community + r_id: 13587 + rule_id: 0oU2x3 + rv_id: 1263624 + url: + https://semgrep.dev/playground/r/6xT29nN/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + version_id: 6xT29nN + shortlink: https://sg.run/3rLb + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-http-request.avoid-tainted-http-request + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - pattern-either: + - patterns: + - pattern: Net::HTTP::$METHOD.new(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: Copy + - pattern: Delete + - pattern: Get + - pattern: Head + - pattern: Lock + - pattern: Mkcol + - pattern: Move + - pattern: Options + - pattern: Patch + - pattern: Post + - pattern: Propfind + - pattern: Proppatch + - pattern: Put + - pattern: Trace + - pattern: Unlock + - patterns: + - pattern: Net::HTTP.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: get + - pattern: get2 + - pattern: head + - pattern: head2 + - pattern: options + - pattern: patch + - pattern: post + - pattern: post2 + - pattern: post_form + - pattern: put + - pattern: request + - pattern: request_get + - pattern: request_head + - pattern: request_post + - pattern: send_request + - pattern: trace + - pattern: get_print + - pattern: get_response + - pattern: start + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + severity: WARNING +- id: ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + languages: + - ruby + message: Using user input when accessing files is potentially dangerous. A malicious actor could use this to modify or + access files they have no right to. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/presidentbeef/brakeman/blob/main/docs/warning_types/file_access/index.markdown + semgrep.dev: + rule: + origin: community + r_id: 13588 + rule_id: KxU72k + rv_id: 1263625 + url: + https://semgrep.dev/playground/r/o5TbDq8/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + version_id: o5TbDq8 + shortlink: https://sg.run/4e8E + source: https://semgrep.dev/r/ruby.rails.security.audit.avoid-tainted-shell-call.avoid-tainted-shell-call + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: Kernel.$X(...) + - patterns: + - pattern-either: + - pattern: Shell.$X(...) + - patterns: + - pattern-inside: "$SHELL = Shell.$ANY(...)\n...\n$SHELL.$X(...)\n" + - pattern: $SHELL.$X(...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-either: + - pattern: cat + - pattern: chdir + - pattern: chroot + - pattern: delete + - pattern: entries + - pattern: exec + - pattern: foreach + - pattern: glob + - pattern: install + - pattern: lchmod + - pattern: lchown + - pattern: link + - pattern: load + - pattern: load_file + - pattern: makedirs + - pattern: move + - pattern: new + - pattern: open + - pattern: read + - pattern: readlines + - pattern: rename + - pattern: rmdir + - pattern: safe_unlink + - pattern: symlink + - pattern: syscopy + - pattern: sysopen + - pattern: system + - pattern: truncate + - pattern: unlink + pattern-sources: + - pattern-either: + - pattern: params[...] + - pattern: cookies + - pattern: request.env + severity: ERROR +- id: ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + languages: + - ruby + message: "Detected string concatenation with a non-literal variable in a pg Ruby SQL statement. This could lead to SQL injection + if the variable is user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries + or prepared statements instead. You can use parameterized queries like so: `conn.exec_params('SELECT $1 AS a, $2 AS b, + $3 AS c', [1, 2, nil])` And you can use prepared statements with `exec_prepared`." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.rubydoc.info/gems/pg/PG/Connection + semgrep.dev: + rule: + origin: community + r_id: 10328 + rule_id: NbUAz7 + rv_id: 1263628 + url: https://semgrep.dev/playground/r/2KTv2y2/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + version_id: 2KTv2y2 + shortlink: https://sg.run/kL0o + source: https://semgrep.dev/r/ruby.rails.security.audit.sqli.ruby-pg-sqli.ruby-pg-sqli + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - SQL Injection + mode: taint + pattern-propagators: + - from: $Y + pattern: $X << $Y + to: $X + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$CON = PG.connect(...)\n...\n" + - pattern-inside: "$CON = PG::Connection.open(...)\n...\n" + - pattern-inside: "$CON = PG::Connection.new(...)\n...\n" + - pattern-either: + - pattern: "$CON.$METHOD($X,...)\n" + - pattern: "$CON.$METHOD $X, ...\n" + - focus-metavariable: $X + - metavariable-regex: + metavariable: $METHOD + regex: ^(exec|exec_params)$ + pattern-sources: + - pattern-either: + - pattern: "params\n" + - pattern: "cookies\n" + severity: WARNING +- id: ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + languages: + - ruby + message: This code includes user input in `link_to`. In Rails 2.x, the body of `link_to` is not escaped. This means + that user input which reaches the body will be executed when the HTML is rendered. Even in other versions, values + starting with `javascript:` or `data:` are not escaped. It is better to create and use a safer function which checks + the body argument. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://brakemanscanner.org/docs/warning_types/link_to/ + - https://brakemanscanner.org/docs/warning_types/link_to_href/ + semgrep.dev: + rule: + origin: community + r_id: 13590 + rule_id: lBU8Qj + rv_id: 1263632 + url: https://semgrep.dev/playground/r/9lT4brj/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + version_id: 9lT4brj + shortlink: https://sg.run/JxXQ + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-link-to.avoid-link-to + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_link_to.rb + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "\"...#{...}...\"\n" + - pattern-not: "\"#{...}...\"\n" + pattern-sinks: + - pattern: link_to(...) + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - pattern-either: + - pattern: $MODEL.url(...) + - pattern: $MODEL.uri(...) + - pattern: $MODEL.link(...) + - pattern: $MODEL.page(...) + - pattern: $MODEL.site(...) + severity: WARNING +- id: ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + languages: + - ruby + message: When a redirect uses user input, a malicious user can spoof a website under a trusted URL or access + restricted parts of a site. When using user-supplied values, sanitize the value before using it for the redirect. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://brakemanscanner.org/docs/warning_types/redirect/ + semgrep.dev: + rule: + origin: community + r_id: 13591 + rule_id: YGUDqJ + rv_id: 1263634 + url: https://semgrep.dev/playground/r/rxTAKdY/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + version_id: rxTAKdY + shortlink: https://sg.run/5DY3 + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-redirect.avoid-redirect + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Open Redirect + mode: taint + pattern-sanitizers: + - pattern: params.merge(:only_path => true) + - pattern: params.merge(:host => ...) + pattern-sinks: + - pattern: redirect_to(...) + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + - patterns: + - pattern: $MODEL.$X(...) + - pattern-not: $MODEL.$X("...") + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: all + - pattern: create + - pattern: create! + - pattern: find + - pattern: find_by_sql + - pattern: first + - pattern: last + - pattern: new + - pattern: from + - pattern: group + - pattern: having + - pattern: joins + - pattern: lock + - pattern: order + - pattern: reorder + - pattern: select + - pattern: where + - pattern: find_by + - pattern: find_by! + - pattern: take + severity: WARNING +- id: ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + languages: + - ruby + message: Avoid rendering user input. It may be possible for a malicious user to input a path that lets them access a + template they shouldn't. To prevent this, check dynamic template paths against a predefined allowlist to make sure + it's an allowed template. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://brakemanscanner.org/docs/warning_types/dynamic_render_paths/ + semgrep.dev: + rule: + origin: community + r_id: 13592 + rule_id: 6JU1bL + rv_id: 1263635 + url: + https://semgrep.dev/playground/r/bZT53p0/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + version_id: bZT53p0 + shortlink: https://sg.run/GO2n + source: https://semgrep.dev/r/ruby.rails.security.audit.xss.avoid-render-dynamic-path.avoid-render-dynamic-path + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: render($X => $INPUT, ...) + - pattern: $INPUT + - metavariable-pattern: + metavariable: $X + pattern-either: + - pattern: action + - pattern: template + - pattern: partial + - pattern: file + pattern-sources: + - pattern: params + - pattern: cookies + - pattern: request.env + severity: WARNING +- id: ruby.rails.security.brakeman.check-before-filter.check-before-filter + languages: + - ruby + message: 'Disabled-by-default Rails controller checks make it much easier to introduce access control mistakes. Prefer an + allowlist approach with `:only => [...]` rather than `except: => [...]`' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-284: Improper Access Control' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 20531 + rule_id: wdUkBP + rv_id: 1263649 + url: + https://semgrep.dev/playground/r/8KT5rDy/ruby.rails.security.brakeman.check-before-filter.check-before-filter + version_id: 8KT5rDy + shortlink: https://sg.run/O4Zn + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-before-filter.check-before-filter + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_skip_before_filter.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Improper Authorization + mode: search + patterns: + - pattern-either: + - pattern: "skip_filter ..., :except => $ARGS\n" + - pattern: "skip_before_filter ..., :except => $ARGS\n" + - pattern: "skip_before_action ..., :except => $ARGS\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + languages: + - generic + message: Found request parameters in a call to `render` in a dynamic context. This can allow end users to request + arbitrary local files which may result in leaking sensitive information persisted on disk. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53ead47f0af821d98b5b41e16d63100c240/test/apps/rails2/app/views/home/test_render.html.erb + semgrep.dev: + rule: + origin: community + r_id: 20043 + rule_id: JDUokO + rv_id: 1263651 + url: + https://semgrep.dev/playground/r/QkTGq9X/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + version_id: QkTGq9X + shortlink: https://sg.run/3QWl + source: + https://semgrep.dev/r/ruby.rails.security.brakeman.check-dynamic-render-local-file-include.check-dynamic-render-local-file-include + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Path Traversal + mode: search + paths: + include: + - '*.erb' + patterns: + - pattern: "params[...]\n" + - pattern-inside: "render :file => ...\n" + severity: WARNING +- id: ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + languages: + - ruby + message: Found an improperly constructed control flow block with `request.get?`. Rails will route HEAD requests as GET + requests but they will fail the `request.get?` check, potentially causing unexpected behavior unless an `elif` + condition is used. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-650: Trusting HTTP Permission Methods on the Server Side' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/accounts_controller.rb + semgrep.dev: + rule: + origin: community + r_id: 20532 + rule_id: x8UdDE + rv_id: 1263652 + url: + https://semgrep.dev/playground/r/3ZT4X82/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + version_id: 3ZT4X82 + shortlink: https://sg.run/eJ6y + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-http-verb-confusion.check-http-verb-confusion + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_verb_confusion.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Other + mode: search + patterns: + - pattern: "if request.get?\n ...\nelse\n ...\nend\n" + - pattern-not-inside: "if ...\nelsif ...\n ...\nend\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + languages: + - ruby + message: Found a string literal assignment to a Rails session secret `$KEY`. Do not commit secret values to source + control! Any user in possession of this value may falsify arbitrary session data in your application. Read this + value from an environment variable, KMS, or file on disk outside of source control. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-540: Inclusion of Sensitive Information in Source Code' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/06-Session_Management_Testing/02-Testing_for_Cookies_Attributes + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails4_with_engines/config/initializers/secret_token.rb + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3/config/initializers/secret_token.rb + semgrep.dev: + rule: + origin: community + r_id: 20155 + rule_id: lBUX1r + rv_id: 1263656 + url: + https://semgrep.dev/playground/r/5PTo1ZY/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + version_id: 5PTo1ZY + shortlink: https://sg.run/KyJd + source: + https://semgrep.dev/r/ruby.rails.security.brakeman.check-rails-session-secret-handling.check-rails-session-secret-handling + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_session_settings.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern: ":$KEY => \"$LITERAL\"\n" + - pattern-inside: "ActionController::Base.session = {...}\n" + - pattern: "$RAILS::Application.config.$KEY = \"$LITERAL\"\n" + - pattern: "Rails.application.config.$KEY = \"$LITERAL\"\n" + - metavariable-regex: + metavariable: $KEY + regex: ^secret(_(token|key_base))?$ + severity: WARNING +- id: ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + languages: + - ruby + message: Found potentially unsafe handling of redirect behavior $X. Do not pass `params` to `redirect_to` without the + `:only_path => true` hash value. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 20732 + rule_id: kxUOJ6 + rv_id: 1263657 + url: https://semgrep.dev/playground/r/GxTke14/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + version_id: GxTke14 + shortlink: https://sg.run/eJNX + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-redirect-to.check-redirect-to + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_redirect.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Open Redirect + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: "$F(...)\n" + - metavariable-pattern: + metavariable: $F + patterns: + - pattern-not-regex: (params|url_for|cookies|request.env|permit|redirect_to) + - pattern: "params.merge! :only_path => true\n...\n" + - pattern: "params.slice(...)\n...\n" + - pattern: "redirect_to [...]\n" + - patterns: + - pattern: "$MODEL. ... .$M(...)\n...\n" + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\w+' + - metavariable-regex: + metavariable: $M + regex: + (all|create|find|find_by|find_by_sql|first|last|new|from|group|having|joins|lock|order|reorder|select|where|take) + - patterns: + - pattern: "params.$UNSAFE_HASH.merge(...,:only_path => true,...)\n...\n" + - metavariable-regex: + metavariable: $UNSAFE_HASH + regex: to_unsafe_h(ash)? + - patterns: + - pattern: params.permit(...,$X,...) + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not-regex: (host|port|(sub)?domain) + pattern-sinks: + - patterns: + - pattern: $X + - pattern-inside: "redirect_to $X, ...\n" + - pattern-not-regex: params\.\w+(? false,...) + severity: WARNING +- id: ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + languages: + - ruby + message: Found a potentially user-controllable argument in the construction of a regular expressions. This may result + in excessive resource consumption when applied to certain inputs, or when the user is allowed to control the match + target. Avoid allowing users to specify regular expressions processed by the server. If you must support + user-controllable input in a regular expression, use an allow-list to restrict the expressions users may supply to + limit catastrophic backtracking. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1333: Inefficient Regular Expression Complexity' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS + semgrep.dev: + rule: + origin: community + r_id: 20156 + rule_id: YGUY4R + rv_id: 1409406 + url: https://semgrep.dev/playground/r/0bTG0WO/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + version_id: 0bTG0WO + shortlink: https://sg.run/qZwx + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-regex-dos.check-regex-dos + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_regex_dos.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Denial-of-Service (DoS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: $Y + - pattern-inside: "/...#{...}.../\n" + - patterns: + - pattern: $Y + - pattern-inside: "Regexp.new(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + - patterns: + - pattern: $Y + - pattern-either: + - pattern-inside: "$RECORD.read_attribute($Y)\n" + - pattern-inside: "$RECORD[$Y]\n" + - metavariable-regex: + metavariable: $RECORD + regex: '[A-Z][a-z]+' + severity: ERROR +- id: ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + languages: + - ruby + message: Found request parameters in a call to `render`. This can allow end users to request arbitrary local files + which may result in leaking sensitive information persisted on disk. Where possible, avoid letting users specify + template paths for `render`. If you must allow user input, use an allow-list of known templates or normalize the + user-supplied value with `File.basename(...)`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_Local_File_Inclusion + - https://github.com/presidentbeef/brakeman/blob/f74cb53/test/apps/rails2/app/controllers/home_controller.rb#L48-L60 + semgrep.dev: + rule: + origin: community + r_id: 20046 + rule_id: ReU2pZ + rv_id: 1409407 + url: + https://semgrep.dev/playground/r/K3TgANN/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + version_id: K3TgANN + shortlink: https://sg.run/Jw8Z + source: + https://semgrep.dev/r/ruby.rails.security.brakeman.check-render-local-file-include.check-render-local-file-include + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_render.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - patterns: + - pattern: $MAP[...] + - metavariable-pattern: + metavariable: $MAP + patterns: + - pattern-not-regex: params + - pattern: File.basename(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "render ..., file: $X\n" + - pattern: "render ..., inline: $X\n" + - pattern: "render ..., template: $X\n" + - pattern: "render ..., action: $X\n" + - pattern: "render $X, ...\n" + - focus-metavariable: $X + pattern-sources: + - patterns: + - pattern: params[...] + severity: WARNING +- id: ruby.rails.security.brakeman.check-secrets.check-secrets + languages: + - ruby + message: Found a Brakeman-style secret - a variable with the name password/secret/api_key/rest_auth_site_key and a + non-empty string literal value. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://github.com/presidentbeef/brakeman/blob/3f5d5d5f00864cdf7769c50f5bd26f1769a4ba75/test/apps/rails3.1/app/controllers/users_controller.rb + semgrep.dev: + rule: + origin: community + r_id: 20047 + rule_id: AbUNqO + rv_id: 1263659 + url: https://semgrep.dev/playground/r/A8TgdBv/ruby.rails.security.brakeman.check-secrets.check-secrets + version_id: A8TgdBv + shortlink: https://sg.run/5ZKl + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-secrets.check-secrets + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_secrets.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: $VAR = "$VALUE" + - metavariable-regex: + metavariable: $VAR + regex: (?i)password|secret|(rest_auth_site|api)_key$ + - metavariable-regex: + metavariable: $VALUE + regex: .+ + severity: WARNING +- id: ruby.rails.security.brakeman.check-send-file.check-send-file + languages: + - ruby + message: Allowing user input to `send_file` allows a malicious user to potentially read arbitrary files from the + server. Avoid accepting user input in `send_file` or normalize with `File.basename(...)` + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-73: External Control of File Name or Path' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/www-community/attacks/Path_Traversal + - https://owasp.org/Top10/A01_2021-Broken_Access_Control/ + semgrep.dev: + rule: + origin: community + r_id: 20048 + rule_id: BYUKbl + rv_id: 1263660 + url: https://semgrep.dev/playground/r/BjTkZRj/ruby.rails.security.brakeman.check-send-file.check-send-file + version_id: BjTkZRj + shortlink: https://sg.run/GbY1 + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-send-file.check-send-file + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_send_file.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Path Traversal + mode: taint + pattern-sinks: + - patterns: + - pattern: "send_file ...\n" + pattern-sources: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-sql.check-sql + languages: + - ruby + message: Found potential SQL injection due to unsafe SQL query construction via $X. Where possible, prefer + parameterized queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/product.rb + semgrep.dev: + rule: + origin: community + r_id: 20533 + rule_id: OrUv2z + rv_id: 1263661 + url: https://semgrep.dev/playground/r/DkTRbE4/ruby.rails.security.brakeman.check-sql.check-sql + version_id: DkTRbE4 + shortlink: https://sg.run/vpgb + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-sql.check-sql + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_sql.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: ":$KEY => $X\n" + - pattern-inside: "[\"...\",$X,...]\n" + - pattern: "params[...].to_i\n" + - pattern: "params[...].to_f\n" + - patterns: + - pattern: "params[...] ? $A : $B\n" + - metavariable-pattern: + metavariable: $A + patterns: + - pattern-not: "params[...]\n" + - metavariable-pattern: + metavariable: $B + patterns: + - pattern-not: "params[...]\n" + pattern-sinks: + - patterns: + - pattern: $X + - pattern-not-inside: "$P.where(\"...\",...)\n" + - pattern-not-inside: "$P.where(:$KEY => $VAL,...)\n" + - pattern-either: + - pattern-inside: "$P.$M(...)\n" + - pattern-inside: "$P.$M(\"...\",...)\n" + - pattern-inside: "class $P < ActiveRecord::Base\n ...\nend\n" + - metavariable-regex: + metavariable: $M + regex: (where|find|first|last|select|minimum|maximum|calculate|sum|average) + pattern-sources: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + languages: + - ruby + message: Found user-controllable input to a reflection method. This may allow a user to alter program behavior and + potentially execute arbitrary instructions in the context of the process. Do not provide arbitrary user input to + `tap`, `method`, or `to_proc` + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails6/app/controllers/groups_controller.rb + semgrep.dev: + rule: + origin: community + r_id: 20534 + rule_id: eqUZ2Q + rv_id: 1263662 + url: + https://semgrep.dev/playground/r/WrTqKLA/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + version_id: WrTqKLA + shortlink: https://sg.run/dPYd + source: + https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection-methods.check-unsafe-reflection-methods + source-rule-url: + https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection_methods.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: "$X. ... .to_proc\n" + - patterns: + - pattern-inside: "$Y.method($Z)\n" + - focus-metavariable: $Z + - patterns: + - pattern-inside: "$Y.tap($Z)\n" + - focus-metavariable: $Z + - patterns: + - pattern-inside: "$Y.tap{ |$ANY| $Z }\n" + - focus-metavariable: $Z + pattern-sources: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + languages: + - ruby + message: Found user-controllable input to Ruby reflection functionality. This allows a remote user to influence + runtime behavior, up to and including arbitrary remote code execution. Do not provide user-controllable input to + reflection functionality. Do not call symbol conversion on user-controllable input. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails2/app/controllers/application_controller.rb + semgrep.dev: + rule: + origin: community + r_id: 20733 + rule_id: wdUkYA + rv_id: 1263663 + url: + https://semgrep.dev/playground/r/0bTKzn8/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + version_id: 0bTKzn8 + shortlink: https://sg.run/vpEX + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unsafe-reflection.check-unsafe-reflection + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unsafe_reflection.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern: $X + - pattern-either: + - pattern-inside: "$X.constantize\n" + - pattern-inside: "$X. ... .safe_constantize\n" + - pattern-inside: "const_get(...)\n" + - pattern-inside: "qualified_const_get(...)\n" + pattern-sources: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + severity: ERROR +- id: ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + languages: + - ruby + message: Found an unscoped `find(...)` with user-controllable input. If the ActiveRecord model being searched against + is sensitive, this may lead to Insecure Direct Object Reference (IDOR) behavior and allow users to read arbitrary + records. Scope the find to the current user, e.g. `current_user.accounts.find(params[:id])`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-639: Authorization Bypass Through User-Controlled Key' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://brakemanscanner.org/docs/warning_types/unscoped_find/ + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/controllers/users_controller.rb + semgrep.dev: + rule: + origin: community + r_id: 20734 + rule_id: x8Ud6d + rv_id: 1263664 + url: + https://semgrep.dev/playground/r/K3TKkxZ/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + version_id: K3TKkxZ + shortlink: https://sg.run/dPbP + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-unscoped-find.check-unscoped-find + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_unscoped_find.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Improper Authorization + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.find(...) + - pattern: $MODEL.find_by_id(...) + - pattern: $MODEL.find_by_id!(...) + - metavariable-regex: + metavariable: $MODEL + regex: '[A-Z]\S+' + pattern-sources: + - pattern-either: + - pattern: "cookies[...]\n" + - patterns: + - pattern: "cookies. ... .$PROPERTY[...]\n" + - metavariable-regex: + metavariable: $PROPERTY + regex: (?!signed|encrypted) + - pattern: "params[...]\n" + - pattern: "request.env[...]\n" + severity: WARNING +- id: ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + languages: + - ruby + message: $V Found an incorrectly-bounded regex passed to `validates_format_of` or `validate ... format => ...`. Ruby + regex behavior is multiline by default and lines should be terminated by `\A` for beginning of line and `\Z` for end + of line, respectively. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-185: Incorrect Regular Expression' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://brakemanscanner.org/docs/warning_types/format_validation/ + - https://github.com/presidentbeef/brakeman/blob/aef6253a8b7bcb97116f2af1ed2a561a6ae35bd5/test/apps/rails3/app/models/account.rb + - https://github.com/presidentbeef/brakeman/blob/main/test/apps/rails3.1/app/models/account.rb + semgrep.dev: + rule: + origin: community + r_id: 20735 + rule_id: OrUv1X + rv_id: 1263665 + url: + https://semgrep.dev/playground/r/qkTR7DG/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + version_id: qkTR7DG + shortlink: https://sg.run/ZPo7 + source: https://semgrep.dev/r/ruby.rails.security.brakeman.check-validation-regex.check-validation-regex + source-rule-url: https://github.com/presidentbeef/brakeman/blob/main/lib/brakeman/checks/check_validation_regex.rb + subcategory: + - vuln + technology: + - ruby + - rails + vulnerability_class: + - Improper Validation + mode: search + patterns: + - pattern-either: + - pattern: "validates ..., :format => <... $V ...>,...\n" + - pattern: "validates_format_of ..., :with => <... $V ...>,...\n" + - metavariable-regex: + metavariable: $V + regex: /(.{2}(? $X,...)\n" + - focus-metavariable: $X + - patterns: + - pattern: "\"$SQLVERB#{$EXPR}...\"\n" + - pattern-not-inside: "$FUNC(\"...\", \"...#{$EXPR}...\",...)\n" + - focus-metavariable: $SQLVERB + - pattern-regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$SQLSTR", $EXPR) + - pattern: "\"$SQLSTR\" + $EXPR\n" + - pattern: "\"$SQLSTR\" % $EXPR\n" + - pattern-not-inside: "$FUNC(\"...\", \"...#{$EXPR}...\",...)\n" + - focus-metavariable: $EXPR + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + severity: ERROR +- id: ruby.rails.security.injection.tainted-url-host.tainted-url-host + languages: + - ruby + message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send + data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with + this request. They could also probe internal servers or other resources that the server running this code can + access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Use the `ssrf_filter` + gem and guard the url construction with `SsrfFilter(...)`, or create an allowlist for approved hosts. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://github.com/arkadiyt/ssrf_filter + semgrep.dev: + rule: + origin: community + r_id: 14705 + rule_id: zdUY0W + rv_id: 1263668 + url: https://semgrep.dev/playground/r/6xT29BN/ruby.rails.security.injection.tainted-url-host.tainted-url-host + version_id: 6xT29BN + shortlink: https://sg.run/RX3g + source: https://semgrep.dev/r/ruby.rails.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - rails + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: SsrfFilter + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: "$URLSTR\n" + - pattern-regex: \w+:\/\/#{.*} + - patterns: + - pattern-either: + - pattern: Kernel::sprintf("$URLSTR", ...) + - pattern: "\"$URLSTR\" + $EXPR\n" + - pattern: "\"$URLSTR\" % $EXPR\n" + - metavariable-pattern: + language: generic + metavariable: $URLSTR + pattern: $SCHEME:// ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: params + - pattern: request + severity: WARNING +- id: scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + languages: + - scala + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://jwt-scala.github.io/jwt-scala/ + semgrep.dev: + rule: + origin: community + r_id: 19040 + rule_id: WAUdK0 + rv_id: 1263669 + url: https://semgrep.dev/playground/r/o5TbDA8/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + version_id: o5TbDA8 + shortlink: https://sg.run/8zE7 + source: https://semgrep.dev/r/scala.jwt-scala.security.jwt-scala-hardcode.jwt-scala-hardcode + subcategory: + - vuln + technology: + - scala + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "import pdi.jwt.$DEPS\n...\n" + - pattern-either: + - pattern: $JWT.encode($X, "...", ...) + - pattern: $JWT.decode($X, "...", ...) + - pattern: $JWT.decodeRawAll($X, "...", ...) + - pattern: $JWT.decodeRaw($X, "...", ...) + - pattern: $JWT.decodeAll($X, "...", ...) + - pattern: $JWT.validate($X, "...", ...) + - pattern: $JWT.isValid($X, "...", ...) + - pattern: $JWT.decodeJson($X, "...", ...) + - pattern: $JWT.decodeJsonAll($X, "...", ...) + - patterns: + - pattern-either: + - pattern: $JWT.encode($X, $KEY, ...) + - pattern: $JWT.decode($X, $KEY, ...) + - pattern: $JWT.decodeRawAll($X, $KEY, ...) + - pattern: $JWT.decodeRaw($X, $KEY, ...) + - pattern: $JWT.decodeAll($X, $KEY, ...) + - pattern: $JWT.validate($X, $KEY, ...) + - pattern: $JWT.isValid($X, $KEY, ...) + - pattern: $JWT.decodeJson($X, $KEY, ...) + - pattern: $JWT.decodeJsonAll($X, $KEY, ...) + - pattern: $JWT.encode($X, this.$KEY, ...) + - pattern: $JWT.decode($X, this.$KEY, ...) + - pattern: $JWT.decodeRawAll($X, this.$KEY, ...) + - pattern: $JWT.decodeRaw($X, this.$KEY, ...) + - pattern: $JWT.decodeAll($X, this.$KEY, ...) + - pattern: $JWT.validate($X, this.$KEY, ...) + - pattern: $JWT.isValid($X, this.$KEY, ...) + - pattern: $JWT.decodeJson($X, this.$KEY, ...) + - pattern: $JWT.decodeJsonAll($X, this.$KEY, ...) + - pattern-either: + - pattern-inside: "class $CL {\n ...\n $KEY = \"...\"\n ...\n}\n" + - pattern-inside: "object $CL {\n ...\n $KEY = \"...\"\n ...\n}\n" + - metavariable-pattern: + metavariable: $JWT + patterns: + - pattern-either: + - pattern: Jwt + - pattern: JwtArgonaut + - pattern: JwtCirce + - pattern: JwtJson4s + - pattern: JwtJson + - pattern: JwtUpickle + severity: WARNING +- id: scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + languages: + - scala + message: Document Builder being instantiated without calling the `setFeature` functions that are generally used for + disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity + Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 19041 + rule_id: 0oUwzP + rv_id: 1263673 + url: + https://semgrep.dev/playground/r/X0TzyRq/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + version_id: X0TzyRq + shortlink: https://sg.run/gRQn + source: https://semgrep.dev/r/scala.lang.security.audit.documentbuilder-dtd-enabled.documentbuilder-dtd-enabled + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + subcategory: + - vuln + technology: + - scala + vulnerability_class: + - XML Injection + patterns: + - pattern-either: + - pattern: "$DF = DocumentBuilderFactory.newInstance(...)\n...\n$DB = $DF.newDocumentBuilder(...)\n" + - patterns: + - pattern: $DB = DocumentBuilderFactory.newInstance(...) + - pattern-not-inside: "...\n$X = $DB.newDocumentBuilder(...)\n" + - pattern: $DB = DocumentBuilderFactory.newInstance(...).newDocumentBuilder(...) + - pattern-not-inside: "...\n$DB.setXIncludeAware(true)\n...\n$DB.setNamespaceAware(true)\n...\n$DB.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\"\ + , true)\n...\n$DB.setFeature(\"http://xml.org/sax/features/external-general-entities\", false)\n...\n$DB.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false)\n" + - pattern-not-inside: "...\n$DB.setXIncludeAware(true)\n...\n$DB.setNamespaceAware(true)\n...\n$DB.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\"\ + , true)\n...\n$DB.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false)\n...\n$DB.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false)\n" + - pattern-not-inside: "...\n$DB.setXIncludeAware(true)\n...\n$DB.setNamespaceAware(true)\n...\n$DB.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false)\n...\n$DB.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true)\n...\n$DB.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false)\n" + - pattern-not-inside: "...\n$DB.setXIncludeAware(true)\n...\n$DB.setNamespaceAware(true)\n...\n$DB.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false)\n...\n$DB.setFeature(\"http://xml.org/sax/features/external-parameter-entities\", false)\n...\n$DB.setFeature(\"\ + http://apache.org/xml/features/disallow-doctype-decl\", true)\n" + severity: WARNING +- id: scala.lang.security.audit.io-source-ssrf.io-source-ssrf + languages: + - scala + message: A parameter being passed directly into `fromURL` most likely lead to SSRF. This could allow an attacker to + send data to their own server, potentially exposing sensitive data sent with this request. They could also probe + internal servers or other resources that the server running this code can access. Do not allow arbitrary hosts. + Instead, create an allowlist for approved hosts, or hardcode the correct host. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + - https://www.scala-lang.org/api/current/scala/io/Source$.html#fromURL(url:java.net.URL)(implicitcodec:scala.io.Codec):scala.io.BufferedSource + semgrep.dev: + rule: + origin: community + r_id: 18486 + rule_id: GdUDOZ + rv_id: 1263675 + url: https://semgrep.dev/playground/r/1QTypG9/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + version_id: 1QTypG9 + shortlink: https://sg.run/Qbz4 + source: https://semgrep.dev/r/scala.lang.security.audit.io-source-ssrf.io-source-ssrf + subcategory: + - audit + technology: + - scala + vulnerability_class: + - Server-Side Request Forgery (SSRF) + patterns: + - pattern-either: + - pattern: Source.fromURL($URL,...) + - pattern: Source.fromURI($URL,...) + - pattern-inside: "import scala.io.$SOURCE\n...\n" + - pattern-either: + - pattern-inside: "def $FUNC(..., $URL: $T, ...) = $A {\n ...\n}\n" + - pattern-inside: "def $FUNC(..., $URL: $T, ...) = {\n ...\n}\n" + severity: WARNING +- id: scala.lang.security.audit.rsa-padding-set.rsa-padding-set + languages: + - scala + message: Usage of RSA without OAEP (Optimal Asymmetric Encryption Padding) may weaken encryption. This could lead to + sensitive data exposure. Instead, use RSA with `OAEPWithMD5AndMGF1Padding` instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-780: Use of RSA Algorithm without OAEP' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + resources: + - https://blog.codacy.com/9-scala-security-issues/ + semgrep.dev: + rule: + origin: community + r_id: 15192 + rule_id: 3qUj1Q + rv_id: 1263677 + url: https://semgrep.dev/playground/r/yeTxpoX/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + version_id: yeTxpoX + shortlink: https://sg.run/GO5p + source: https://semgrep.dev/r/scala.lang.security.audit.rsa-padding-set.rsa-padding-set + subcategory: + - audit + technology: + - scala + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "$VAR = $CIPHER.getInstance($MODE)\n" + - metavariable-regex: + metavariable: $MODE + regex: .*RSA/.*/NoPadding.* + severity: WARNING +- id: scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + languages: + - scala + message: XML processor being instantiated without calling the `setFeature` functions that are generally used for + disabling entity processing. User controlled data in XML Parsers can result in XML Internal Entity Processing + vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery (SSRF), + port scanning. Make sure to disable entity processing functionality. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 19042 + rule_id: KxUrkq + rv_id: 1263678 + url: https://semgrep.dev/playground/r/rxTAKWY/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + version_id: rxTAKWY + shortlink: https://sg.run/QbYP + source: https://semgrep.dev/r/scala.lang.security.audit.sax-dtd-enabled.sax-dtd-enabled + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + subcategory: + - audit + technology: + - scala + vulnerability_class: + - XML Injection + patterns: + - pattern-either: + - pattern: $SR = new SAXReader(...) + - pattern: "$SF = SAXParserFactory.newInstance(...)\n...\n$SR = $SF.newSAXParser(...)\n" + - patterns: + - pattern: $SR = SAXParserFactory.newInstance(...) + - pattern-not-inside: "...\n$X = $SR.newSAXParser(...)\n" + - pattern: $SR = SAXParserFactory.newInstance(...).newSAXParser(...) + - pattern: $SR = new SAXBuilder(...) + - pattern-not-inside: "...\n$SR.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true)\n...\n$SR.setFeature(\"\ + http://xml.org/sax/features/external-general-entities\", false)\n...\n$SR.setFeature(\"http://xml.org/sax/features/external-parameter-entities\"\ + , false)\n" + - pattern-not-inside: "...\n$SR.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\", true)\n...\n$SR.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false)\n...\n$SR.setFeature(\"http://xml.org/sax/features/external-general-entities\"\ + , false)\n" + - pattern-not-inside: "...\n$SR.setFeature(\"http://xml.org/sax/features/external-general-entities\", false)\n...\n$SR.setFeature(\"\ + http://apache.org/xml/features/disallow-doctype-decl\", true)\n...\n$SR.setFeature(\"http://xml.org/sax/features/external-parameter-entities\"\ + , false)\n" + - pattern-not-inside: "...\n$SR.setFeature(\"http://xml.org/sax/features/external-general-entities\", false)\n...\n$SR.setFeature(\"\ + http://xml.org/sax/features/external-parameter-entities\", false)\n...\n$SR.setFeature(\"http://apache.org/xml/features/disallow-doctype-decl\"\ + , true)\n" + severity: WARNING +- id: scala.lang.security.audit.scalac-debug.scalac-debug + languages: + - generic + message: Scala applications built with `debug` set to true in production may leak debug information to attackers. + Debug mode also affects performance and reliability. Remove it from configuration. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-489: Active Debug Code' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A05:2021 - Security Misconfiguration + references: + - https://docs.scala-lang.org/overviews/compiler-options/index.html + semgrep.dev: + rule: + origin: community + r_id: 18686 + rule_id: JDUlE0 + rv_id: 946569 + url: https://semgrep.dev/playground/r/qkT4j0N/scala.lang.security.audit.scalac-debug.scalac-debug + version_id: qkT4j0N + shortlink: https://sg.run/QbGd + source: https://semgrep.dev/r/scala.lang.security.audit.scalac-debug.scalac-debug + subcategory: + - audit + technology: + - scala + - sbt + vulnerability_class: + - Active Debug Code + paths: + include: + - '*.sbt*' + patterns: + - pattern-either: + - pattern: scalacOptions ... "-Vdebug" + - pattern: scalacOptions ... "-Ydebug" + severity: WARNING +- id: scala.lang.security.audit.tainted-sql-string.tainted-sql-string + languages: + - scala + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + semgrep.dev: + rule: + origin: community + r_id: 20050 + rule_id: WAUY8B + rv_id: 1263682 + url: https://semgrep.dev/playground/r/w8TRoO6/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + version_id: w8TRoO6 + shortlink: https://sg.run/ALD6 + source: https://semgrep.dev/r/scala.lang.security.audit.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - scala + vulnerability_class: + - SQL Injection + mode: taint + pattern-sanitizers: + - pattern-either: + - patterns: + - pattern-either: + - pattern: $LOGGER.$METHOD(...) + - pattern: $LOGGER(...) + - metavariable-regex: + metavariable: $LOGGER + regex: (i?)log.* + - patterns: + - pattern: $LOGGER.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (i?)(trace|info|warn|warning|warnToError|error|debug) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - patterns: + - pattern-inside: "$SB = new StringBuilder(\"$SQLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\"\n...\n" + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern-either: + - pattern: s"..." + - pattern: f"..." + - pattern-regex: ".*\\b(?i)(select|delete|insert|create|update|alter|drop)\\b.*\n" + - pattern-not-inside: println(...) + - pattern-not-inside: throw new $EXCEPTION(...) + pattern-sources: + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = $A {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = $A(...) {\n ...\n}\n" + severity: ERROR +- id: scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + languages: + - scala + message: XMLInputFactory being instantiated without calling the setProperty functions that are generally used for + disabling entity processing. User controlled data in XML Document builder can result in XML Internal Entity + Processing vulnerabilities like the disclosure of confidential data, denial of service, Server Side Request Forgery + (SSRF), port scanning. Make sure to disable entity processing functionality. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 19043 + rule_id: qNUQ7w + rv_id: 1263683 + url: + https://semgrep.dev/playground/r/xyTjzkA/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + version_id: xyTjzkA + shortlink: https://sg.run/3BEb + source: https://semgrep.dev/r/scala.lang.security.audit.xmlinputfactory-dtd-enabled.xmlinputfactory-dtd-enabled + source-rule-url: https://cheatsheetseries.owasp.org//cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html + subcategory: + - audit + technology: + - scala + vulnerability_class: + - XML Injection + patterns: + - pattern-not-inside: "...\n$XMLFACTORY.setProperty(\"javax.xml.stream.isSupportingExternalEntities\", false)\n" + - pattern-either: + - pattern: $XMLFACTORY = XMLInputFactory.newFactory(...) + - pattern: $XMLFACTORY = XMLInputFactory.newInstance(...) + - pattern: $XMLFACTORY = new XMLInputFactory(...) + severity: WARNING +- id: scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + languages: + - generic + message: Possibly bypassable CSRF configuration found. CSRF is an attack that forces an end user to execute unwanted + actions on a web application in which they’re currently authenticated. Make sure that Content-Type black list is + configured and CORS filter is turned on. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.playframework.com/documentation/2.8.x/Migration25#CSRF-changes + - https://owasp.org/www-community/attacks/csrf + semgrep.dev: + rule: + origin: community + r_id: 19044 + rule_id: lBUyRR + rv_id: 1263684 + url: + https://semgrep.dev/playground/r/O9Tpx53/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + version_id: O9Tpx53 + shortlink: https://sg.run/4DEE + source: https://semgrep.dev/r/scala.play.security.conf-csrf-headers-bypass.conf-csrf-headers-bypass + subcategory: + - vuln + technology: + - scala + - play + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + paths: + include: + - '*.conf' + patterns: + - pattern-either: + - pattern: X-Requested-With = "*" + - pattern: Csrf-Token = "..." + - pattern-inside: "bypassHeaders {...\n...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"application/x-www-form-urlencoded\"...\"multipart/form-data\"\ + ...\"text/plain\"...]\n ...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"application/x-www-form-urlencoded\"...\"text/plain\"...\"multipart/form-data\"\ + ...]\n ...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"multipart/form-data\"...\"application/x-www-form-urlencoded\"\ + ...\"text/plain\"...]\n ...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"multipart/form-data\"...\"text/plain\"...\"application/x-www-form-urlencoded\"\ + ...]\n ...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"text/plain\"...\"application/x-www-form-urlencoded\"...\"multipart/form-data\"\ + ...]\n ...\n...}\n" + - pattern-not-inside: "{...\n ...\n ...blackList = [...\"text/plain\"...\"multipart/form-data\"...\"application/x-www-form-urlencoded\"\ + ...]\n ...\n...}\n" + severity: ERROR +- id: scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + languages: + - generic + message: Session cookie `Secure` flag is explicitly disabled. The `secure` flag for cookies prevents the client from + transmitting the cookie over insecure channels such as HTTP. Set the `Secure` flag by setting `secure` to `true` in + configuration file. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#security + - https://www.playframework.com/documentation/2.8.x/SettingsSession#Session-Configuration + semgrep.dev: + rule: + origin: community + r_id: 18284 + rule_id: GdUDJO + rv_id: 1263685 + url: + https://semgrep.dev/playground/r/e1TyjJv/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + version_id: e1TyjJv + shortlink: https://sg.run/8z8N + source: https://semgrep.dev/r/scala.play.security.conf-insecure-cookie-settings.conf-insecure-cookie-settings + subcategory: + - vuln + technology: + - play + - scala + vulnerability_class: + - Cookie Security + paths: + include: + - '*.conf' + patterns: + - pattern: secure = false + - pattern-inside: "session = {\n ...\n}\n" + severity: WARNING +- id: scala.play.security.tainted-html-response.tainted-html-response + languages: + - scala + message: Detected a request with potential user-input going into an `Ok()` response. This bypasses any view or + template environments, including HTML escaping, which may expose this application to cross-site scripting (XSS) + vulnerabilities. Consider using a view technology such as Twirl which automatically escapes HTML views. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18795 + rule_id: 0oUwn2 + rv_id: 1263686 + url: https://semgrep.dev/playground/r/vdT06yj/scala.play.security.tainted-html-response.tainted-html-response + version_id: vdT06yj + shortlink: https://sg.run/BG96 + source: https://semgrep.dev/r/scala.play.security.tainted-html-response.tainted-html-response + subcategory: + - vuln + technology: + - scala + - play + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern-either: + - pattern: org.apache.commons.lang3.StringEscapeUtils.escapeHtml4(...) + - pattern: org.owasp.encoder.Encode.forHtml(...) + pattern-sinks: + - pattern-either: + - pattern: Html.apply(...) + - pattern: Ok(...).as(HTML) + - pattern: Ok(...).as(ContentTypes.HTML) + - patterns: + - pattern: Ok(...).as($CTYPE) + - metavariable-regex: + metavariable: $CTYPE + regex: '"[tT][eE][xX][tT]/[hH][tT][mM][lL]"' + - patterns: + - pattern: Ok(...).as($CTYPE) + - pattern-not: Ok(...).as("...") + - pattern-either: + - pattern-inside: "def $FUNC(..., $URL: $T, ...) = $A {\n ...\n}\n" + - pattern-inside: "def $FUNC(..., $URL: $T, ...) = {\n ...\n}\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {\n ...\n}\n" + severity: WARNING +- id: scala.play.security.tainted-slick-sqli.tainted-slick-sqli + languages: + - scala + message: Detected a tainted SQL statement. This could lead to SQL injection if variables in the SQL statement are not + properly sanitized. Avoid using using user input for generating SQL strings. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://scala-slick.org/doc/3.3.3/sql.html#splicing-literal-values + - https://scala-slick.org/doc/3.2.0/sql-to-slick.html#non-optimal-sql-code + semgrep.dev: + rule: + origin: community + r_id: 18328 + rule_id: GdUDWO + rv_id: 1263687 + url: https://semgrep.dev/playground/r/d6TyxJe/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + version_id: d6TyxJe + shortlink: https://sg.run/k9K2 + source: https://semgrep.dev/r/scala.play.security.tainted-slick-sqli.tainted-slick-sqli + subcategory: + - vuln + technology: + - scala + - slick + - play + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $MODEL.overrideSql(...) + - pattern: sql"..." + - pattern-inside: "import slick.$DEPS\n...\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {\n ...\n}\n" + severity: ERROR +- id: scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + languages: + - scala + message: User data flows into this manually-constructed SQL string. User data can be safely inserted into SQL strings + using prepared statements or an object-relational mapper (ORM). Manually-constructed SQL strings is a possible + indicator of SQL injection, which could let an attacker steal or manipulate data from the database. Instead, use + prepared statements (`connection.PreparedStatement`) or a safe library. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.oracle.com/javase/7/docs/api/java/sql/PreparedStatement.html + semgrep.dev: + rule: + origin: community + r_id: 20051 + rule_id: 0oUpon + rv_id: 1263688 + url: + https://semgrep.dev/playground/r/ZRTKAoG/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + version_id: ZRTKAoG + shortlink: https://sg.run/BeW9 + source: https://semgrep.dev/r/scala.play.security.tainted-sql-from-http-request.tainted-sql-from-http-request + subcategory: + - vuln + technology: + - scala + - play + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - patterns: + - pattern-inside: "$SB = new StringBuilder(\"$SQLSTR\");\n...\n" + - pattern: $SB.append(...) + - patterns: + - pattern-inside: "$VAR = \"$SQLSTR\"\n...\n" + - pattern: $VAR += ... + - metavariable-regex: + metavariable: $SQLSTR + regex: (?i)(select|delete|insert|create|update|alter|drop)\b + - patterns: + - pattern: s"..." + - pattern-regex: ".*\\b(?i)(select|delete|insert|create|update|alter|drop)\\b.*\n" + - pattern-not-inside: println(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern: $REQ + - pattern-either: + - pattern-inside: "Action {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async {\n $REQ: Request[$T] => \n ...\n}\n" + - pattern-inside: "Action.async(...) {\n $REQ: Request[$T] => \n ...\n}\n" + - patterns: + - pattern: $PARAM + - pattern-either: + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action(...) {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async {\n ...\n}\n" + - pattern-inside: "def $CTRL(..., $PARAM: $TYPE, ...) = Action.async(...) {\n ...\n}\n" + severity: ERROR +- id: scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + languages: + - scala + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 15079 + rule_id: OrU6W1 + rv_id: 1263691 + url: https://semgrep.dev/playground/r/7ZTE3kr/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + version_id: 7ZTE3kr + shortlink: https://sg.run/Z40o + source: https://semgrep.dev/r/scala.scala-jwt.security.jwt-hardcode.scala-jwt-hardcoded-secret + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "com.auth0.jwt.algorithms.Algorithm.HMAC256(\"...\");\n" + - pattern: "$SECRET = \"...\";\n...\ncom.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);\n" + - pattern: "class $CLASS {\n ...\n $DECL $SECRET = \"...\";\n ...\n def $FUNC (...): $RETURNTYPE = {\n ...\n com.auth0.jwt.algorithms.Algorithm.HMAC256($SECRET);\n\ + \ ...\n }\n ...\n}\n" + - pattern: "com.auth0.jwt.algorithms.Algorithm.HMAC384(\"...\");\n" + - pattern: "$SECRET = \"...\";\n...\ncom.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);\n" + - pattern: "class $CLASS {\n ...\n $DECL $SECRET = \"...\";\n ...\n def $FUNC (...): $RETURNTYPE = {\n ...\n com.auth0.jwt.algorithms.Algorithm.HMAC384($SECRET);\n\ + \ ...\n }\n ...\n}\n" + - pattern: "com.auth0.jwt.algorithms.Algorithm.HMAC512(\"...\");\n" + - pattern: "$SECRET = \"...\";\n...\ncom.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);\n" + - pattern: "class $CLASS {\n ...\n $DECL $SECRET = \"...\";\n ...\n def $FUNC (...): $RETURNTYPE = {\n ...\n com.auth0.jwt.algorithms.Algorithm.HMAC512($SECRET);\n\ + \ ...\n }\n ...\n}\n" + severity: ERROR +- id: solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + languages: + - solidity + message: Missing check for 'from' and 'to' being the same before updating balances could lead to incorrect balance + manipulation on self-transfers. Include a check to ensure 'from' and 'to' are not the same before updating balances + to prevent balance manipulation during self-transfers. + metadata: + category: security + confidence: HIGH + cwe: 'CWE-682: Incorrect Calculation' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A7:2021 Identification and Authentication Failures + references: + - https://blog.verichains.io/p/miner-project-attacked-by-vulnerabilities + - https://x.com/shoucccc/status/1757777764646859121 + semgrep.dev: + rule: + origin: community + r_id: 133075 + rule_id: 6JUv7Nz + rv_id: 946620 + url: + https://semgrep.dev/playground/r/A8TJzYz/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + version_id: A8TJzYz + shortlink: https://sg.run/Or6X7 + source: https://semgrep.dev/r/solidity.security.missing-self-transfer-check-ercx.missing-self-transfer-check-ercx + subcategory: + - vuln + technology: + - blockchain + - solidity + vulnerability_class: + - Other + patterns: + - pattern-either: + - pattern: "_balances[$FROM] = $FROM_BALANCE - value;\n" + - pattern: "_balances[$TO] = $TO_BALANCE + value;\n" + - pattern-not-inside: "if ($FROM != $TO) {\n ...\n _balances[$FROM] = $FROM_BALANCE - value;\n ...\n _balances[$TO] + = $TO_BALANCE + value;\n ...\n}\n" + - pattern-inside: "function _update(address $FROM, address $TO, uint256 value, bool mint) internal virtual {\n ...\n}\n" + severity: ERROR +- id: swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + languages: + - swift + message: Potentially sensitive data was observed to be stored in UserDefaults, which is not adequate protection of + sensitive information. For data of a sensitive nature, applications should leverage the Keychain. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + masvs: + - 'MASVS-STORAGE-1: The app securely stores sensitive data' + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/ValidatingInput.html + - https://mas.owasp.org/MASVS/controls/MASVS-STORAGE-1/ + semgrep.dev: + rule: + origin: community + r_id: 66512 + rule_id: KxUqoZ + rv_id: 1263696 + url: + https://semgrep.dev/playground/r/3ZT4Xy2/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + version_id: 3ZT4Xy2 + shortlink: https://sg.run/qvoO + source: https://semgrep.dev/r/swift.lang.storage.sensitive-storage-userdefaults.swift-user-defaults + subcategory: + - vuln + technology: + - ios + - macos + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(passcode|password|pass_word|passphrase|pass_code|pass_word|pass_phrase)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(api_key|apikey)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(secretkey|secret_key|secrettoken|secret_token|clientsecret|client_secret)$ + - focus-metavariable: $KEY + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $VALUE + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $VALUE + - patterns: + - pattern-either: + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set(\"$VALUE\", forKey: $KEY)\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: \"$KEY\")\n" + - pattern: "UserDefaults.standard.set($VALUE, forKey: $KEY)\n" + - metavariable-regex: + metavariable: $KEY + regex: (?i).*(cryptkey|cryptokey|crypto_key|cryptionkey|symmetrickey|privatekey|symmetric_key|private_key)$ + - focus-metavariable: $KEY + severity: WARNING +- id: terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + languages: + - hcl + message: Detected an AWS CloudFront Distribution with an insecure TLS version. TLS versions less than 1.2 are + considered insecure because they can be broken. To fix this, set your `minimum_protocol_version` to `"TLSv1.2_2018", + "TLSv1.2_2019", "TLSv1.2_2021", "TLSv1.2_2025" or "TLSv1.3_2025"`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17342 + rule_id: kxU6A8 + rv_id: 1263700 + url: + https://semgrep.dev/playground/r/5PTo1bY/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + version_id: 5PTo1bY + shortlink: https://sg.run/Q6o4 + source: + https://semgrep.dev/r/terraform.aws.security.aws-cloudfront-insecure-tls.aws-insecure-cloudfront-distribution-tls-version + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n \ + \ minimum_protocol_version = \"TLSv1.2_2018\"\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n \ + \ minimum_protocol_version = \"TLSv1.2_2019\"\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n \ + \ minimum_protocol_version = \"TLSv1.2_2021\"\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n \ + \ minimum_protocol_version = \"TLSv1.2_2025\"\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudfront_distribution\" $ANYTHING {\n ...\n viewer_certificate {\n ...\n \ + \ minimum_protocol_version = \"TLSv1.3_2025\"\n ...\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + languages: + - hcl + message: The AWS CloudWatch Log Group has no retention. Missing retention in log groups can cause losing important + event information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17344 + rule_id: x8UGBG + rv_id: 946665 + url: + https://semgrep.dev/playground/r/BjT1N2B/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + version_id: BjT1N2B + shortlink: https://sg.run/4lwl + source: + https://semgrep.dev/r/terraform.aws.security.aws-cloudwatch-log-group-no-retention.aws-cloudwatch-log-group-no-retention + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_cloudwatch_log_group\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_cloudwatch_log_group\" $ANYTHING {\n ...\n retention_in_days = ...\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + languages: + - hcl + message: The AWS CodeBuild Project is unencrypted. The AWS KMS encryption key protects projects in the CodeBuild. To + create your own, create a aws_kms_key resource or use the ARN string of a key in your account. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17347 + rule_id: v8U4kG + rv_id: 946669 + url: + https://semgrep.dev/playground/r/K3TJbNr/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + version_id: K3TJbNr + shortlink: https://sg.run/5yxA + source: + https://semgrep.dev/r/terraform.aws.security.aws-codebuild-project-unencrypted.aws-codebuild-project-unencrypted + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_codebuild_project\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_codebuild_project\" $ANYTHING {\n ...\n encryption_key = ...\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + languages: + - hcl + message: The AWS configuration aggregator does not aggregate all AWS Config region. This may result in unmonitored + configuration in regions that are thought to be unused. Configure the aggregator with all_regions for the source. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-778: Insufficient Logging' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 47275 + rule_id: DbUo7v + rv_id: 1263703 + url: + https://semgrep.dev/playground/r/A8Tgdwv/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + version_id: A8Tgdwv + shortlink: https://sg.run/O6A7 + source: + https://semgrep.dev/r/terraform.aws.security.aws-config-aggregator-not-all-regions.aws-config-aggregator-not-all-regions + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Insufficient Logging + pattern-either: + - pattern: "resource \"aws_config_configuration_aggregator\" $ANYTHING {\n ...\n account_aggregation_source {\n ...\n\ + \ regions = ...\n ...\n }\n ...\n}\n" + - pattern: "resource \"aws_config_configuration_aggregator\" $ANYTHING {\n ...\n organization_aggregation_source {\n \ + \ ...\n regions = ...\n ...\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + languages: + - hcl + message: Database instance has no logging. Missing logs can cause missing important event information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + semgrep.dev: + rule: + origin: community + r_id: 17348 + rule_id: d8U4RA + rv_id: 1263704 + url: + https://semgrep.dev/playground/r/BjTkZ6j/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + version_id: BjTkZ6j + shortlink: https://sg.run/GyAp + source: https://semgrep.dev/r/terraform.aws.security.aws-db-instance-no-logging.aws-db-instance-no-logging + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_db_instance\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_db_instance\" $ANYTHING {\n ...\n enabled_cloudwatch_logs_exports = [$SOMETHING, + ...]\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + languages: + - hcl + message: Auditing is not enabled for DocumentDB. To ensure that you are able to accurately audit the usage of your + DocumentDB cluster, you should enable auditing and export logs to CloudWatch. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-778: Insufficient Logging' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#enabled_cloudwatch_logs_exports + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 48630 + rule_id: AbU1WN + rv_id: 1263705 + url: + https://semgrep.dev/playground/r/DkTRbA4/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + version_id: DkTRbA4 + shortlink: https://sg.run/xJYP + source: + https://semgrep.dev/r/terraform.aws.security.aws-documentdb-auditing-disabled.aws-documentdb-auditing-disabled + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Insufficient Logging + patterns: + - pattern: "resource \"aws_docdb_cluster\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_docdb_cluster\" $ANYTHING {\n ...\n enabled_cloudwatch_logs_exports = [..., \"audit\"\ + , ...]\n ...\n}\n" + severity: INFO +- id: terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + languages: + - hcl + message: By default, AWS DynamoDB Table is encrypted using AWS-managed keys. However, for added security, it's + recommended to configure your own AWS KMS encryption key to protect your data in the DynamoDB table. You can either + create a new aws_kms_key resource or use the ARN of an existing key in your AWS account to do so. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17350 + rule_id: nJUGe2 + rv_id: 1263707 + url: + https://semgrep.dev/playground/r/0bTKzj8/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + version_id: 0bTKzj8 + shortlink: https://sg.run/Ay4p + source: https://semgrep.dev/r/terraform.aws.security.aws-dynamodb-table-unencrypted.aws-dynamodb-table-unencrypted + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_dynamodb_table\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_dynamodb_table\" $ANYTHING {\n ...\n server_side_encryption {\n enabled = true\n\ + \ kms_key_arn = ...\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + languages: + - hcl + message: Ensure EBS Snapshot is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in + terms of access and rotation. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17351 + rule_id: EwUqko + rv_id: 946677 + url: + https://semgrep.dev/playground/r/A8TJzb0/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + version_id: A8TJzb0 + shortlink: https://sg.run/ByPW + source: + https://semgrep.dev/r/terraform.aws.security.aws-ebs-snapshot-encrypted-with-cmk.aws-ebs-snapshot-encrypted-with-cmk + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_ebs_snapshot_copy\" $ANYTHING {\n ...\n encrypted = true\n ...\n}\n" + - pattern-not-inside: "resource \"aws_ebs_snapshot_copy\" $ANYTHING {\n ...\n encrypted = true\n kms_key_id = ...\n \ + \ ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + languages: + - hcl + message: The AWS EBS is unencrypted. The AWS EBS encryption protects data in the EBS. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17352 + rule_id: 7KUW7K + rv_id: 946678 + url: https://semgrep.dev/playground/r/BjT1N2v/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + version_id: BjT1N2v + shortlink: https://sg.run/Dy5Y + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-unencrypted.aws-ebs-unencrypted + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_ebs_encryption_by_default\" $ANYTHING {\n ...\n enabled = false\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + languages: + - hcl + message: The AWS EBS volume is unencrypted. The volume, the disk I/O and any derived snapshots could be read if + compromised. Volumes should be encrypted to ensure sensitive data is stored securely. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_volume#encrypted + - https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html + semgrep.dev: + rule: + origin: community + r_id: 50759 + rule_id: YGUKl1 + rv_id: 1263708 + url: + https://semgrep.dev/playground/r/K3TKk1Z/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + version_id: K3TKk1Z + shortlink: https://sg.run/6ZbY + source: https://semgrep.dev/r/terraform.aws.security.aws-ebs-volume-unencrypted.aws-ebs-volume-unencrypted + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_ebs_volume\" $ANYTHING {\n ...\n}\n" + - pattern-not: "resource \"aws_ebs_volume\" $ANYTHING {\n ...\n encrypted = true\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + languages: + - hcl + message: EC2 instances should not have a public IP address attached in order to block public access to the instances. + To fix this, set your `associate_public_ip_address` to `"false"`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 17354 + rule_id: 8GUA2n + rv_id: 1263709 + url: https://semgrep.dev/playground/r/qkTR73G/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + version_id: qkTR73G + shortlink: https://sg.run/08rv + source: https://semgrep.dev/r/terraform.aws.security.aws-ec2-has-public-ip.aws-ec2-has-public-ip + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Other + patterns: + - pattern-either: + - pattern: "resource \"aws_instance\" $ANYTHING {\n ...\n associate_public_ip_address = true\n ...\n}\n" + - pattern: "resource \"aws_launch_template\" $ANYTHING {\n ...\n network_interfaces {\n ...\n associate_public_ip_address + = true\n ...\n }\n ...\n}\n" + severity: WARNING +- id: + terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + languages: + - hcl + message: The EC2 launch template has Instance Metadata Service Version 1 (IMDSv1) enabled. IMDSv2 introduced session + authentication tokens which improve security when talking to IMDS. You should either disable IMDS or require the use + of IMDSv2. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1390: Weak Authentication' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata_options + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + semgrep.dev: + rule: + origin: community + r_id: 50762 + rule_id: zdU0Wo + rv_id: 1263712 + url: + https://semgrep.dev/playground/r/JdTzx88/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + version_id: JdTzx88 + shortlink: https://sg.run/pg9J + source: + https://semgrep.dev/r/terraform.aws.security.aws-ec2-launch-template-metadata-service-v1-enabled.aws-ec2-launch-template-metadata-service-v1-enabled + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Improper Authentication + patterns: + - pattern: "resource \"aws_launch_template\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_launch_template\" $ANYTHING {\n ...\n metadata_options {\n ...\n http_endpoint + = \"disabled\"\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_launch_template\" $ANYTHING {\n ...\n metadata_options {\n ...\n http_tokens + = \"required\"\n ...\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + languages: + - hcl + message: The ECR repository allows tag mutability. Image tags could be overwritten with compromised images. ECR images + should be set to IMMUTABLE to prevent code injection through image mutation. This can be done by setting + `image_tag_mutability` to IMMUTABLE. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-345: Insufficient Verification of Data Authenticity' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository#image_tag_mutability + - https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 48635 + rule_id: KxUB4o + rv_id: 1263716 + url: + https://semgrep.dev/playground/r/A8Tgdwd/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + version_id: A8Tgdwd + shortlink: https://sg.run/ZEeL + source: https://semgrep.dev/r/terraform.aws.security.aws-ecr-mutable-image-tags.aws-ecr-mutable-image-tags + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Improper Authentication + patterns: + - pattern: "resource \"aws_ecr_repository\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_ecr_repository\" $ANYTHING {\n ...\n image_tag_mutability = \"IMMUTABLE\"\n ...\n\ + }\n" + severity: WARNING +- id: terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + languages: + - hcl + message: Detected wildcard access granted in your ECR repository policy principal. This grants access to all users, + including anonymous users (public access). Instead, limit principals, actions and resources to what you need + according to least privilege. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ecr_repository_policy + - https://docs.aws.amazon.com/lambda/latest/operatorguide/wildcard-permissions-iam.html + - https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/monitor-amazon-ecr-repositories-for-wildcard-permissions-using-aws-cloudformation-and-aws-config.html + - https://cwe.mitre.org/data/definitions/732.html + semgrep.dev: + rule: + origin: community + r_id: 48636 + rule_id: qNUzov + rv_id: 1263717 + url: + https://semgrep.dev/playground/r/BjTkZ6A/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + version_id: BjTkZ6A + shortlink: https://sg.run/nzqb + source: + https://semgrep.dev/r/terraform.aws.security.aws-ecr-repository-wildcard-principal.aws-ecr-repository-wildcard-principal + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_ecr_repository_policy\" $ANYTHING {\n ...\n}\n" + - pattern-either: + - patterns: + - pattern: policy = "$JSONPOLICY" + - metavariable-pattern: + language: json + metavariable: $JSONPOLICY + patterns: + - pattern-not-inside: "{..., \"Effect\": \"Deny\", ...}\n" + - pattern-either: + - pattern: "{..., \"Principal\": \"*\", ...}\n" + - pattern: "{..., \"Principal\": [..., \"*\", ...], ...}\n" + - pattern: "{..., \"Principal\": { \"AWS\": \"*\" }, ...}\n" + - pattern: "{..., \"Principal\": { \"AWS\": [..., \"*\", ...] }, ...}\n" + - patterns: + - pattern-inside: policy = jsonencode(...) + - pattern-not-inside: "{..., Effect = \"Deny\", ...}\n" + - pattern-either: + - pattern: "{..., Principal = \"*\", ...}\n" + - pattern: "{..., Principal = [..., \"*\", ...], ...}\n" + - pattern: "{..., Principal = { AWS = \"*\" }, ...}\n" + - pattern: "{..., Principal = { AWS = [..., \"*\", ...] }, ...}\n" + severity: WARNING +- id: terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + languages: + - hcl + message: Ensure EFS filesystem is encrypted at rest using KMS CMKs. CMKs gives you control over the encryption key in + terms of access and rotation. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17355 + rule_id: gxUJ4n + rv_id: 946690 + url: + https://semgrep.dev/playground/r/2KTYbWy/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + version_id: 2KTYbWy + shortlink: https://sg.run/Kk07 + source: + https://semgrep.dev/r/terraform.aws.security.aws-efs-filesystem-encrypted-with-cmk.aws-efs-filesystem-encrypted-with-cmk + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_efs_file_system\" $ANYTHING {\n ...\n encrypted = true\n ...\n}\n" + - pattern-not-inside: "resource \"aws_efs_file_system\" $ANYTHING {\n ...\n encrypted = true\n kms_key_id = ...\n ...\n\ + }\n" + severity: WARNING +- id: terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + languages: + - terraform + message: Detected an AWS Elasticsearch domain using an insecure version of TLS. To fix this, set "tls_security_policy" + equal to "Policy-Min-TLS-1-2-2019-07". + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 19045 + rule_id: YGUle7 + rv_id: 1263718 + url: + https://semgrep.dev/playground/r/DkTRbA5/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + version_id: DkTRbA5 + shortlink: https://sg.run/PYlq + source: + https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-insecure-tls-version.aws-elasticsearch-insecure-tls-version + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + pattern: "resource \"aws_elasticsearch_domain\" $ANYTHING {\n ...\n domain_endpoint_options {\n ...\n enforce_https + = true\n tls_security_policy = \"Policy-Min-TLS-1-0-2019-07\"\n ...\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + languages: + - hcl + message: "Ensure all Elasticsearch has node-to-node encryption enabled.\t" + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17357 + rule_id: 3qU6J7 + rv_id: 1263719 + url: + https://semgrep.dev/playground/r/WrTqK0v/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + version_id: WrTqK0v + shortlink: https://sg.run/lp3y + source: + https://semgrep.dev/r/terraform.aws.security.aws-elasticsearch-nodetonode-encryption.aws-elasticsearch-nodetonode-encryption-not-enabled + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "resource \"aws_elasticsearch_domain\" $ANYTHING {\n ...\n node_to_node_encryption {\n ...\n enabled + = false\n ...\n }\n ...\n}\n" + - pattern: "resource \"aws_elasticsearch_domain\" $ANYTHING {\n ...\n cluster_config {\n ...\n instance_count + = $COUNT\n ...\n }\n}\n" + - pattern-not-inside: "resource \"aws_elasticsearch_domain\" $ANYTHING {\n ...\n cluster_config {\n ...\n instance_count + = $COUNT\n ...\n }\n node_to_node_encryption {\n ...\n enabled = true\n ...\n }\n}\n" + - metavariable-comparison: + comparison: $COUNT > 1 + metavariable: $COUNT + severity: WARNING +- id: terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + languages: + - hcl + message: 'Detected wildcard access granted to Glacier Vault. This means anyone within your AWS account ID can perform actions + on Glacier resources. Instead, limit to a specific identity in your account, like this: `arn:aws:iam:::`.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/732.html + semgrep.dev: + rule: + origin: community + r_id: 17364 + rule_id: AbUeYK + rv_id: 1263723 + url: + https://semgrep.dev/playground/r/l4TJRGB/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + version_id: l4TJRGB + shortlink: https://sg.run/XN9K + source: https://semgrep.dev/r/terraform.aws.security.aws-glacier-vault-any-principal.aws-glacier-vault-any-principal + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_glacier_vault\" $ANYTHING {\n ...\n}\n" + - pattern: access_policy = "$STATEMENT" + - metavariable-pattern: + language: json + metavariable: $STATEMENT + patterns: + - pattern-inside: "{..., \"Effect\": \"Allow\", ...}\n" + - pattern-either: + - pattern: "\"Principal\": \"*\"\n" + - pattern: "\"Principal\": {..., \"AWS\": \"*\", ...}\n" + - pattern-inside: "\"Principal\": {..., \"AWS\": ..., ...}\n" + - pattern-regex: "(^\\\"arn:aws:iam::\\*:(.*)\\\"$)\n" + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + languages: + - hcl + message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative + actions. Instead, limit actions and resources to what you need according to least privilege. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/732.html + semgrep.dev: + rule: + origin: community + r_id: 17365 + rule_id: BYUzY5 + rv_id: 1263724 + url: + https://semgrep.dev/playground/r/YDTZe9q/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + version_id: YDTZe9q + shortlink: https://sg.run/jzgY + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy-ssoadmin.aws-iam-admin-policy-ssoadmin + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_ssoadmin_permission_set_inline_policy\" $ANYTHING {\n ...\n}\n" + - pattern: inline_policy = "$STATEMENT" + - metavariable-pattern: + language: json + metavariable: $STATEMENT + patterns: + - pattern-not-inside: "{..., \"Effect\": \"Deny\", ...}\n" + - pattern-either: + - pattern: "{..., \"Action\": [..., \"*\", ...], \"Resource\": [..., \"*\", ...], ...}\n" + - pattern: "{..., \"Action\": \"*\", \"Resource\": \"*\", ...}\n" + - pattern: "{..., \"Action\": \"*\", \"Resource\": [...], ...}\n" + - pattern: "{..., \"Action\": [...], \"Resource\": \"*\", ...}\n" + severity: ERROR +- id: terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + languages: + - hcl + message: Detected admin access granted in your policy. This means anyone with this policy can perform administrative + actions. Instead, limit actions and resources to what you need according to least privilege. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/732.html + semgrep.dev: + rule: + origin: community + r_id: 17366 + rule_id: DbUx8l + rv_id: 1263725 + url: https://semgrep.dev/playground/r/6xT29Pv/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + version_id: 6xT29Pv + shortlink: https://sg.run/1zbw + source: https://semgrep.dev/r/terraform.aws.security.aws-iam-admin-policy.aws-iam-admin-policy + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_iam_policy\" $ANYTHING {\n ...\n}\n" + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + language: json + metavariable: $STATEMENT + patterns: + - pattern-not-inside: "{..., \"Effect\": \"Deny\", ...}\n" + - pattern-either: + - pattern: "{..., \"Action\": [..., \"*\", ...], \"Resource\": [..., \"*\", ...], ...}\n" + - pattern: "{..., \"Action\": \"*\", \"Resource\": \"*\", ...}\n" + - pattern: "{..., \"Action\": \"*\", \"Resource\": [...], ...}\n" + - pattern: "{..., \"Action\": [...], \"Resource\": \"*\", ...}\n" + severity: ERROR +- id: terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + languages: + - terraform + message: Detected AWS API Gateway to be using an insecure version of TLS. To fix this issue make sure to set + "security_policy" equal to "TLS_1_2". + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 18818 + rule_id: v8UOle + rv_id: 1263726 + url: + https://semgrep.dev/playground/r/o5TbD8k/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + version_id: o5TbD8k + shortlink: https://sg.run/p98J + source: + https://semgrep.dev/r/terraform.aws.security.aws-insecure-api-gateway-tls-version.aws-insecure-api-gateway-tls-version + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "resource \"aws_api_gateway_domain_name\" $ANYTHING {\n ...\n security_policy = \"...\"\n ...\n}\n" + - pattern: "resource \"aws_apigatewayv2_domain_name\" $ANYTHING {\n ...\n domain_name_configuration {...}\n ...\n\ + }\n" + - pattern-not: "resource \"aws_api_gateway_domain_name\" $ANYTHING {\n ...\n security_policy = \"TLS_1_2\"\ + \n ...\n }\n" + - pattern-not: "resource \"aws_apigatewayv2_domain_name\" $ANYTHING {\n ...\n domain_name_configuration {\n\ + \ ...\n security_policy = \"TLS_1_2\"\n ...\n }\n }\n" + severity: WARNING +- id: terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + languages: + - hcl + message: Detected an AWS Redshift configuration with a SSL disabled. To fix this, set your `require_ssl` to `"true"`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17368 + rule_id: 0oUrOj + rv_id: 1263727 + url: + https://semgrep.dev/playground/r/zyTb27A/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + version_id: zyTb27A + shortlink: https://sg.run/yPYx + source: + https://semgrep.dev/r/terraform.aws.security.aws-insecure-redshift-ssl-configuration.aws-insecure-redshift-ssl-configuration + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_redshift_parameter_group\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_redshift_parameter_group\" $ANYTHING {\n ...\n parameter {\n name = \"require_ssl\"\ + \n value = \"true\"\n }\n ...\n}\n" + - pattern-not-inside: "resource \"aws_redshift_parameter_group\" $ANYTHING {\n ...\n parameter {\n name = \"require_ssl\"\ + \n value = true\n }\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + languages: + - hcl + message: The AWS Kinesis stream does not encrypt data at rest. The data could be read if the Kinesis stream storage + layer is compromised. Enable Kinesis stream server-side encryption. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://owasp.org/Top10/A04_2021-Insecure_Design + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/kinesis_stream#encryption_type + - https://docs.aws.amazon.com/streams/latest/dev/server-side-encryption.html + rule-origin-note: published from /src/aws-kinesis-stream-unencrypted.yml in None + semgrep.dev: + rule: + origin: community + r_id: 52199 + rule_id: 8GU72N + rv_id: 1263728 + url: + https://semgrep.dev/playground/r/pZT037O/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + version_id: pZT037O + shortlink: https://sg.run/KZ0L + source: https://semgrep.dev/r/terraform.aws.security.aws-kinesis-stream-unencrypted.aws-kinesis-stream-unencrypted + subcategory: + - audit + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "resource \"aws_kinesis_stream\" $ANYTHING {\n ...\n}\n" + - pattern-not: "resource \"aws_kinesis_stream\" $ANYTHING {\n ...\n encryption_type = \"KMS\"\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + languages: + - hcl + message: Detected wildcard access granted in your KMS key. This means anyone with this policy can perform + administrative actions over the keys. Instead, limit principals, actions and resources to what you need according to + least privilege. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://cwe.mitre.org/data/definitions/732.html + semgrep.dev: + rule: + origin: community + r_id: 17371 + rule_id: lBUWPD + rv_id: 1263729 + url: + https://semgrep.dev/playground/r/2KTv2J4/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + version_id: 2KTv2J4 + shortlink: https://sg.run/Nwlp + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-key-wildcard-principal.aws-kms-key-wildcard-principal + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_kms_key\" $ANYTHING {\n ...\n}\n" + - pattern: policy = "$STATEMENT" + - metavariable-pattern: + language: json + metavariable: $STATEMENT + patterns: + - pattern-not-inside: "{..., \"Effect\": \"Deny\", ...}\n" + - pattern-either: + - pattern: "{..., \"Principal\": \"*\", \"Action\": \"kms:*\", \"Resource\": \"*\", ...}\n" + - pattern: "{..., \"Principal\": [..., \"*\", ...], \"Action\": \"kms:*\", \"Resource\": \"*\", ...}\n" + - pattern: "{..., \"Principal\": { \"AWS\": \"*\" }, \"Action\": \"kms:*\", \"Resource\": \"*\", ...}\n" + - pattern: "{..., \"Principal\": { \"AWS\": [..., \"*\", ...] }, \"Action\": \"kms:*\", \"Resource\": \"*\", ...}\n" + severity: ERROR +- id: terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + languages: + - hcl + message: The AWS KMS has no rotation. Missing rotation can cause leaked key to be used by attackers. To fix this, set + a `enable_key_rotation`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 17372 + rule_id: PeU0L3 + rv_id: 1263730 + url: https://semgrep.dev/playground/r/X0Tzy67/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + version_id: X0Tzy67 + shortlink: https://sg.run/kz47 + source: https://semgrep.dev/r/terraform.aws.security.aws-kms-no-rotation.aws-kms-no-rotation + subcategory: + - vuln + technology: + - aws + - terraform + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "resource \"aws_kms_key\" $ANYTHING {\n ...\n enable_key_rotation = false\n ...\n}\n" + - pattern: "resource \"aws_kms_key\" $ANYTHING {\n ...\n customer_master_key_spec = \"SYMMETRIC_DEFAULT\"\n enable_key_rotation + = false\n ...\n}\n" + - pattern: "resource \"aws_kms_key\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"aws_kms_key\" $ANYTHING {\n ...\n enable_key_rotation = true\n ...\n}\n" + - pattern-not-inside: "resource \"aws_kms_key\" $ANYTHING {\n ...\n customer_master_key_spec = \"RSA_2096\"\n ...\n}\n" + severity: WARNING +- id: terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials + languages: + - hcl + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 17373 + rule_id: JDU6gj + rv_id: 1263731 + url: + https://semgrep.dev/playground/r/jQTn573/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials + version_id: jQTn573 + shortlink: https://sg.run/wZqY + source: + https://semgrep.dev/r/terraform.aws.security.aws-lambda-environment-credentials.aws-lambda-environment-credentials + subcategory: + - vuln + technology: + - aws + - terraform + - secrets + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "resource \"$ANYTING\" $ANYTHING {\n ...\n environment {\n variables = {\n ...\n }\n }\n\ + \ ...\n}\n" + - pattern-either: + - pattern-inside: "AWS_ACCESS_KEY_ID = \"$Y\"\n" + - pattern-regex: "(?:root`.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://rhinosecuritylabs.com/aws/assume-worst-aws-assume-role-enumeration/ + semgrep.dev: + rule: + origin: community + r_id: 15139 + rule_id: 5rUL1P + rv_id: 1263749 + url: https://semgrep.dev/playground/r/LjTkg8D/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + version_id: LjTkg8D + shortlink: https://sg.run/LXWr + source: https://semgrep.dev/r/terraform.aws.security.wildcard-assume-role.wildcard-assume-role + subcategory: + - vuln + technology: + - aws + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "resource \"aws_iam_role\" $NAME {\n ...\n}\n" + - pattern: assume_role_policy = "$STATEMENT" + - metavariable-pattern: + language: json + metavariable: $STATEMENT + patterns: + - pattern-inside: "{..., \"Effect\": \"Allow\", ..., \"Action\": \"sts:AssumeRole\", ...}\n" + - pattern: "\"Principal\": {..., \"AWS\": \"*\", ...}\n" + severity: ERROR +- id: terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + languages: + - hcl + message: Enabling authentication ensures that all communications in the application are authenticated. The + `auth_settings` block needs to be filled out with the appropriate auth backend settings + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-287: Improper Authentication' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#auth_settings + semgrep.dev: + rule: + origin: community + r_id: 15102 + rule_id: 0oU23p + rv_id: 1263755 + url: + https://semgrep.dev/playground/r/PkTR3P8/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + version_id: PkTR3P8 + shortlink: https://sg.run/JxYw + source: + https://semgrep.dev/r/terraform.azure.security.appservice.appservice-authentication-enabled.appservice-authentication-enabled + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Improper Authentication + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n auth_settings {\n ...\n enabled = true\n\ + \ ...\n }\n...\n}\n" + - pattern-either: + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n auth_settings {\n ...\n enabled = false\n\ + \ ...\n }\n...\n}\n" + severity: ERROR +- id: terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + languages: + - hcl + message: Use the latest version of HTTP to ensure you are benefiting from security fixes. Add `http2_enabled = true` + to your appservice resource block + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#http2_enabled + semgrep.dev: + rule: + origin: community + r_id: 15103 + rule_id: KxU7LJ + rv_id: 1263756 + url: + https://semgrep.dev/playground/r/JdTzx98/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + version_id: JdTzx98 + shortlink: https://sg.run/5DkA + source: https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-http2.appservice-enable-http2 + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Improper Validation + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n site_config {\n ...\n http2_enabled = true\n\ + \ ...\n }\n...\n}\n" + - pattern-either: + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n site_config {\n ...\n http2_enabled = false\n\ + \ ...\n }\n...\n}\n" + severity: INFO +- id: terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + languages: + - hcl + message: By default, clients can connect to App Service by using both HTTP or HTTPS. HTTP should be disabled enabling + the HTTPS Only setting. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#https_only + - https://docs.microsoft.com/en-us/azure/app-service/configure-ssl-bindings#enforce-https + semgrep.dev: + rule: + origin: community + r_id: 15104 + rule_id: qNUXwx + rv_id: 1263757 + url: + https://semgrep.dev/playground/r/5PTo1gg/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + version_id: 5PTo1gg + shortlink: https://sg.run/GOKp + source: + https://semgrep.dev/r/terraform.azure.security.appservice.appservice-enable-https-only.appservice-enable-https-only + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n https_only = true\n...\n}\n" + - pattern-either: + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n https_only = false\n...\n}\n" + severity: ERROR +- id: terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + languages: + - hcl + message: Detected an AppService that was not configured to use a client certificate. Add `client_cert_enabled = true` + in your resource block. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#client_cert_enabled + semgrep.dev: + rule: + origin: community + r_id: 15105 + rule_id: lBU8D6 + rv_id: 1263758 + url: + https://semgrep.dev/playground/r/GxTkedE/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + version_id: GxTkedE + shortlink: https://sg.run/RX1O + source: + https://semgrep.dev/r/terraform.azure.security.appservice.appservice-require-client-cert.appservice-require-client-cert + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Improper Authentication + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n client_cert_enabled = true\n...\n}\n" + - pattern-either: + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n client_cert_enabled = false\n...\n}\n" + severity: INFO +- id: terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + languages: + - hcl + message: Detected an AppService that was not configured to use TLS 1.2. Add `site_config.min_tls_version = "1.2"` in + your resource block. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/app_service#min_tls_version + semgrep.dev: + rule: + origin: community + r_id: 15106 + rule_id: YGUDbZ + rv_id: 1263759 + url: + https://semgrep.dev/playground/r/RGT0L4x/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + version_id: RGT0L4x + shortlink: https://sg.run/AXRp + source: + https://semgrep.dev/r/terraform.azure.security.appservice.appservice-use-secure-tls-policy.appservice-use-secure-tls-policy + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: min_tls_version = $ANYTHING + - pattern-inside: "resource \"azurerm_app_service\" \"$NAME\" {\n ...\n}\n" + - pattern-not-inside: min_tls_version = "1.2" + severity: ERROR +- id: + terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + languages: + - hcl + message: Ensure that App service enables detailed error messages + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-778: Insufficient Logging' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures + semgrep.dev: + rule: + origin: community + r_id: 23962 + rule_id: bwU1Eg + rv_id: 1263762 + url: + https://semgrep.dev/playground/r/DkTRbr5/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + version_id: DkTRbr5 + shortlink: https://sg.run/pA1g + source: + https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-detailed-errormessages-enabled.azure-appservice-detailed-errormessages-enabled + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Insufficient Logging + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\nlogs {\n ...\n detailed_error_messages_enabled + = true\n ...\n}\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + languages: + - hcl + message: Ensure web app redirects all HTTP traffic to HTTPS in Azure App Service Slot + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23966 + rule_id: x8UZRP + rv_id: 1263766 + url: + https://semgrep.dev/playground/r/qkTR78q/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + version_id: qkTR78q + shortlink: https://sg.run/1g9w + source: + https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-https-only.azure-appservice-https-only + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_app_service\" \"...\" {\n...\nhttps_only = true\n...\n}\n" + - pattern-inside: "resource \"azurerm_app_service\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + languages: + - hcl + message: Ensure web app is using the latest version of TLS encryption + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23969 + rule_id: v8UNL7 + rv_id: 1263769 + url: + https://semgrep.dev/playground/r/6xT29gv/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + version_id: 6xT29gv + shortlink: https://sg.run/rDwn + source: + https://semgrep.dev/r/terraform.azure.security.appservice.azure-appservice-min-tls-version.azure-appservice-min-tls-version + subcategory: + - audit + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "\"1.0\"\n" + - pattern: "\"1.1\"\n" + - pattern-inside: min_tls_version = ... + - pattern-inside: "$RESOURCE \"azurerm_app_service\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + languages: + - hcl + message: Ensure that the expiration date is set on all keys + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23990 + rule_id: 0oUlgp + rv_id: 946834 + url: + https://semgrep.dev/playground/r/pZTNGkl/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + version_id: pZTNGkl + shortlink: https://sg.run/J1vw + source: https://semgrep.dev/r/terraform.azure.security.azure-key-no-expiration-date.azure-key-no-expiration-date + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: resource + - pattern-not-inside: "resource \"azurerm_key_vault_key\" \"...\" {\n...\nexpiration_date = \"...\"\n...\n}\n" + - pattern-inside: "resource \"azurerm_key_vault_key\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + languages: + - hcl + message: Ensure MSSQL is using the latest version of TLS encryption + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23995 + rule_id: 6JUJG8 + rv_id: 1263784 + url: + https://semgrep.dev/playground/r/xyTjzeR/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + version_id: xyTjzeR + shortlink: https://sg.run/B1lW + source: + https://semgrep.dev/r/terraform.azure.security.azure-mssql-service-mintls-version.azure-mssql-service-mintls-version + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "\"1.0\"\n" + - pattern: "\"1.1\"\n" + - pattern-inside: minimum_tls_version = ... + - pattern-inside: "$RESOURCE \"azurerm_mssql_server\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + languages: + - hcl + message: Ensure that MySQL server enables infrastructure encryption + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-320: CWE CATEGORY: Key Management Errors' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23996 + rule_id: oqUloL + rv_id: 946840 + url: + https://semgrep.dev/playground/r/yeT0vBn/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + version_id: yeT0vBn + shortlink: https://sg.run/Dd6Y + source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-encryption-enabled.azure-mysql-encryption-enabled + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: resource + - pattern-inside: "resource \"azurerm_mysql_server\" \"...\" {\n...\n}\n" + - pattern-not-inside: "resource \"azurerm_mysql_server\" \"...\" {\n...\ninfrastructure_encryption_enabled = true\n...\n\ + }\n" + severity: WARNING +- id: terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + languages: + - hcl + message: Ensure MySQL is using the latest version of TLS encryption + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 23997 + rule_id: zdU8NN + rv_id: 1263785 + url: + https://semgrep.dev/playground/r/O9TpxWE/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + version_id: O9TpxWE + shortlink: https://sg.run/WR44 + source: https://semgrep.dev/r/terraform.azure.security.azure-mysql-mintls-version.azure-mysql-mintls-version + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: "\"TLS1_0\"\n" + - pattern: "\"TLS1_1\"\n" + - pattern-inside: ssl_minimal_tls_version_enforced = ... + - pattern-inside: "$RESOURCE \"azurerm_mysql_server\" \"...\" {\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + languages: + - hcl + message: Detected a Storage that was not configured to deny action by default. Add `enable_https_traffic_only = true` + in your resource block. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#enable_https_traffic_only + - https://docs.microsoft.com/en-us/azure/storage/common/storage-require-secure-transfer + semgrep.dev: + rule: + origin: community + r_id: 15110 + rule_id: pKUpDA + rv_id: 1263805 + url: + https://semgrep.dev/playground/r/BjTkZ0A/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + version_id: BjTkZ0A + shortlink: https://sg.run/0y9v + source: https://semgrep.dev/r/terraform.azure.security.storage.storage-enforce-https.storage-enforce-https + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-not-inside: "resource \"azurerm_storage_account\" \"...\" {\n...\n enable_https_traffic_only = true\n...\n}\n" + - pattern-inside: "resource \"azurerm_storage_account\" \"...\" {\n...\n enable_https_traffic_only = false\n...\n}\n" + severity: WARNING +- id: terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + languages: + - hcl + message: 'Azure Storage currently supports three versions of the TLS protocol: 1.0, 1.1, and 1.2. Azure Storage uses TLS + 1.2 on public HTTPS endpoints, but TLS 1.0 and TLS 1.1 are still supported for backward compatibility. This check will + warn if the minimum TLS is not set to TLS1_2.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/storage_account#min_tls_version + - https://docs.microsoft.com/en-us/azure/storage/common/transport-layer-security-configure-minimum-version + semgrep.dev: + rule: + origin: community + r_id: 15155 + rule_id: AbUQdL + rv_id: 1263807 + url: + https://semgrep.dev/playground/r/WrTqKpv/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + version_id: WrTqKpv + shortlink: https://sg.run/KXD7 + source: + https://semgrep.dev/r/terraform.azure.security.storage.storage-use-secure-tls-policy.storage-use-secure-tls-policy + subcategory: + - vuln + technology: + - terraform + - azure + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern-inside: "resource \"azurerm_storage_account\" \"...\" {\n ...\n min_tls_version = \"$ANYTHING\"\n ...\n}\n" + - pattern-inside: "resource \"azurerm_storage_account\" \"...\" {\n ...\n}\n" + - pattern-not-inside: "resource \"azurerm_storage_account\" \"...\" {\n ...\n min_tls_version = \"TLS1_2\"\n ...\n}\n" + severity: ERROR +- id: terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + languages: + - hcl + message: Ensure bucket logs access. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-778: Insufficient Logging' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A10:2017 - Insufficient Logging & Monitoring + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://docs.bridgecrew.io/docs/google-cloud-policy-index + semgrep.dev: + rule: + origin: community + r_id: 32303 + rule_id: gxUrdg + rv_id: 1263813 + url: + https://semgrep.dev/playground/r/JdTzxRN/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + version_id: JdTzxRN + shortlink: https://sg.run/5g5D + source: https://semgrep.dev/r/terraform.gcp.security.gcp-cloud-storage-logging.gcp-cloud-storage-logging + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Insufficient Logging + patterns: + - pattern: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n}\n" + - pattern-not-inside: "resource \"google_storage_bucket\" $ANYTHING {\n ...\n logging {\n log_bucket = ...\n } \ + \ \n ...\n}\n" + severity: WARNING +- id: terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + languages: + - hcl + message: "Ensure that RSASHA1 is not used for the zone-signing and key-signing keys in Cloud DNS DNSSEC\t" + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 33670 + rule_id: 7KUZZb + rv_id: 1263837 + url: + https://semgrep.dev/playground/r/bZT53oD/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + version_id: bZT53oD + shortlink: https://sg.run/bKKW + source: https://semgrep.dev/r/terraform.gcp.security.gcp-dns-key-specs-rsasha1.gcp-dns-key-specs-rsasha1 + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: resource + - pattern-inside: "resource \"google_dns_managed_zone\" \"...\" {\n...\ndnssec_config {\n ...\n default_key_specs + {\n ...\n algorithm = \"rsasha1\"\n key_type = \"zoneSigning\"\n ...\n }\n ...\n\ + }\n...\n}\n" + - pattern-inside: "resource \"google_dns_managed_zone\" \"...\" {\n...\ndnssec_config {\n ...\n default_key_specs + {\n ...\n algorithm = \"rsasha1\"\n key_type = \"keySigning\"\n ...\n }\n ...\n\ + }\n...\n}\n" + severity: WARNING +- id: terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + languages: + - hcl + message: Ensure all Cloud SQL database instance requires all incoming connections to use SSL + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 33709 + rule_id: v8Uod5 + rv_id: 1263873 + url: + https://semgrep.dev/playground/r/pZT033e/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + version_id: pZT033e + shortlink: https://sg.run/W4Yg + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-require-ssl.gcp-sql-database-require-ssl + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: resource + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n}\n" + - pattern-not-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n\ + \ require_ssl = true\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n\ + \ ssl_mode = ...\n ...\n }\n ...\n}\n" + severity: WARNING +- fix: "\"TRUSTED_CLIENT_CERTIFICATE_REQUIRED\"\n" + id: + terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + languages: + - hcl + message: Ensure all Cloud SQL database instance require incoming connections to use SSL. To enable this for + PostgresSQL and MySQL, use `ssl_mode="TRUSTED_CLIENT_CERTIFICATE_REQUIRED"`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 153509 + rule_id: 5rUdGAz + rv_id: 1263874 + url: + https://semgrep.dev/playground/r/2KTv22E/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + version_id: 2KTv22E + shortlink: https://sg.run/WANR2 + source: + https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-postgres-mysql.gcp-sql-database-ssl-insecure-value-postgres-mysql + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n database_version = \"$DB\"\n ...\n\ + }\n" + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n \ + \ ssl_mode = $VALUE\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n\ + \ ssl_mode = \"TRUSTED_CLIENT_CERTIFICATE_REQUIRED\"\n ...\n }\n ...\n}\n" + - metavariable-regex: + metavariable: $DB + regex: .*(MYSQL|POSTGRES).* + - focus-metavariable: $VALUE + severity: WARNING +- fix: "\"ENCRYPTED_ONLY\"\n" + id: terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + languages: + - hcl + message: Ensure all Cloud SQL database instance require incoming connections to use SSL. For SQL Server, + `ssl_mode="ENCRYPTED_ONLY"` is the most secure value that is supported. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cloud.google.com/sql/docs/postgres/admin-api/rest/v1/instances#ipconfiguration + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 153510 + rule_id: GdUvX6A + rv_id: 1263875 + url: + https://semgrep.dev/playground/r/X0Tzyyl/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + version_id: X0Tzyyl + shortlink: https://sg.run/0o92j + source: + https://semgrep.dev/r/terraform.gcp.security.gcp-sql-database-ssl-insecure-value-sqlserver.gcp-sql-database-ssl-insecure-value-sqlserver + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n database_version = \"$DB\"\n ...\n\ + }\n" + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n \ + \ ssl_mode = $VALUE\n ...\n }\n ...\n}\n" + - pattern-not-inside: "resource \"google_sql_database_instance\" \"...\" {\n ...\n ip_configuration {\n ...\n\ + \ ssl_mode = \"ENCRYPTED_ONLY\"\n ...\n }\n ...\n}\n" + - metavariable-regex: + metavariable: $DB + regex: .*(SQLSERVER).* + - focus-metavariable: $VALUE + severity: WARNING +- id: terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + languages: + - hcl + message: Ensure that Cloud SQL database Instances are not open to the world + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1220: Insufficient Granularity of Access Control' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 33710 + rule_id: d8U7Ll + rv_id: 1263876 + url: + https://semgrep.dev/playground/r/jQTn559/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + version_id: jQTn559 + shortlink: https://sg.run/0Xv5 + source: https://semgrep.dev/r/terraform.gcp.security.gcp-sql-public-database.gcp-sql-public-database + subcategory: + - vuln + technology: + - terraform + - gcp + vulnerability_class: + - Other + patterns: + - pattern: resource + - pattern-either: + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n...\nip_configuration {\n ...\n authorized_networks + {\n ...\n value = \"0.0.0.0/0\"\n ...\n }\n ...\n}\n...\n}\n" + - pattern-inside: "resource \"google_sql_database_instance\" \"...\" {\n...\nip_configuration {\n ...\n dynamic \"authorized_networks\"\ + \ {\n ...\n content {\n ...\n value = \"0.0.0.0/0\"\n ...\n }\n ...\n }\n ...\n}\n...\n\ + }\n" + severity: WARNING +- id: terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + languages: + - hcl + message: AWS EC2 Instance allowing use of the IMDSv1 + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/instance#metadata-options + semgrep.dev: + rule: + origin: community + r_id: 11302 + rule_id: GdU0eA + rv_id: 1263884 + url: https://semgrep.dev/playground/r/w8TRooE/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + version_id: w8TRooE + shortlink: https://sg.run/J3BQ + source: https://semgrep.dev/r/terraform.lang.security.ec2-imdsv1-optional.ec2-imdsv1-optional + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Server-Side Request Forgery (SSRF) + pattern-either: + - patterns: + - pattern: http_tokens = "optional" + - pattern-inside: "metadata_options { ... }\n" + - patterns: + - pattern: "resource \"aws_instance\" \"$NAME\" {\n ...\n}\n" + - pattern-not: "resource \"aws_instance\" \"$NAME\" {\n ...\n metadata_options {\n ...\n http_tokens = \"required\"\ + \n ...\n }\n ...\n}\n" + - pattern-not: "resource \"aws_instance\" \"$NAME\" {\n ...\n metadata_options {\n ...\n http_tokens = \"optional\"\ + \n ...\n }\n ...\n}\n" + - pattern-not: "resource \"aws_instance\" \"$NAME\" {\n ...\n metadata_options {\n ...\n http_endpoint = \"disabled\"\ + \n ...\n }\n ...\n}\n" + severity: ERROR +- id: terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + languages: + - hcl + message: RDS instance or cluster with hardcoded credentials in source code. It is recommended to pass the credentials + at runtime, or generate random credentials using the random_password resource. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#master_password + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/rds_cluster#master_password + - https://registry.terraform.io/providers/hashicorp/random/latest/docs/resources/password + semgrep.dev: + rule: + origin: community + r_id: 15830 + rule_id: OrUl6W + rv_id: 1263896 + url: + https://semgrep.dev/playground/r/gETB77b/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + version_id: gETB77b + shortlink: https://sg.run/x4qA + source: + https://semgrep.dev/r/terraform.lang.security.rds-insecure-password-storage-in-source-code.rds-insecure-password-storage-in-source-code + subcategory: + - vuln + technology: + - terraform + - aws + - secrets + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern: password = "..." + - pattern-inside: "resource \"aws_db_instance\" \"...\" {\n ...\n}\n" + - patterns: + - pattern: master_password = "..." + - pattern-inside: "resource \"aws_rds_cluster\" \"...\" {\n ...\n}\n" + severity: WARNING +- id: terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + languages: + - hcl + message: S3 bucket with public read-write access detected. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#acl + - https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl + semgrep.dev: + rule: + origin: community + r_id: 9754 + rule_id: 6JUqvn + rv_id: 1263900 + url: https://semgrep.dev/playground/r/PkTR3y5/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + version_id: PkTR3y5 + shortlink: https://sg.run/0nok + source: https://semgrep.dev/r/terraform.lang.security.s3-public-rw-bucket.s3-public-rw-bucket + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Mishandled Sensitive Information + pattern: acl = "public-read-write" + severity: ERROR +- id: terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + languages: + - hcl + message: This rule has been deprecated, as all s3 buckets are encrypted by default with no way to disable it. See + https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_server_side_encryption_configuration + for more info. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + deprecated: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket#server_side_encryption_configuration + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html + semgrep.dev: + rule: + origin: community + r_id: 16202 + rule_id: 3qU62L + rv_id: 1263901 + url: + https://semgrep.dev/playground/r/JdTzxjN/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + version_id: JdTzxjN + shortlink: https://sg.run/Jezw + source: https://semgrep.dev/r/terraform.lang.security.s3-unencrypted-bucket.s3-unencrypted-bucket + subcategory: + - vuln + technology: + - terraform + - aws + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: a + - pattern: b + severity: INFO +- id: typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + languages: + - typescript + message: Detected the use of `$TRUST`. This can introduce a Cross-Site-Scripting (XSS) vulnerability if this comes + from user-provided input. If you have to use `$TRUST`, ensure it does not come from user-input or use the + appropriate prevention mechanism e.g. input validation or sanitization depending on the context. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://angular.io/api/platform-browser/DomSanitizer + - https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9755 + rule_id: oqUzgA + rv_id: 1263902 + url: + https://semgrep.dev/playground/r/5PTo1zk/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + version_id: 5PTo1zk + shortlink: https://sg.run/KWxP + source: https://semgrep.dev/r/typescript.angular.security.audit.angular-domsanitizer.angular-bypasssecuritytrust + subcategory: + - vuln + technology: + - angular + - browser + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern: sanitizer.sanitize(...) + - pattern-not: sanitizer.sanitize(SecurityContext.NONE, ...); + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $X.$TRUST($Y) + - focus-metavariable: $Y + - pattern-not: "$X.$TRUST(`...`)\n" + - pattern-not: "$X.$TRUST(\"...\")\n" + - metavariable-regex: + metavariable: $TRUST + regex: + (bypassSecurityTrustHtml|bypassSecurityTrustStyle|bypassSecurityTrustScript|bypassSecurityTrustUrl|bypassSecurityTrustResourceUrl) + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X: string, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X: string, ...) { ... }\n" + - focus-metavariable: $X + severity: WARNING +- id: typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + languages: + - typescript + message: 'Add "encryption: $Y.BucketEncryption.KMS_MANAGED" or "encryption: $Y.BucketEncryption.S3_MANAGED" to the bucket + props for Bucket construct $X' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + semgrep.dev: + rule: + origin: community + r_id: 15276 + rule_id: bwU8qz + rv_id: 1263903 + url: + https://semgrep.dev/playground/r/GxTkeRx/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + version_id: GxTkeRx + shortlink: https://sg.run/eowX + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-encryption.awscdk-bucket-encryption + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3'\n...\n" + - pattern: const $X = new Bucket(...) + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.KMS, ...})\n" + - pattern-not: "const $X = new Bucket(..., {..., encryption: BucketEncryption.S3_MANAGED, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3'\n...\n" + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.KMS, ...})\n" + - pattern-not: "const $X = new $Y.Bucket(..., {..., encryption: $Y.BucketEncryption.S3_MANAGED, ...})\n" + severity: ERROR +- id: typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + languages: + - ts + message: Bucket $X is not set to enforce encryption-in-transit, if not explictly setting this on the bucket policy - + the property "enforceSSL" should be set to true + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html + semgrep.dev: + rule: + origin: community + r_id: 15277 + rule_id: NbUN8B + rv_id: 1263904 + url: + https://semgrep.dev/playground/r/RGT0Llg/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + version_id: RGT0Llg + shortlink: https://sg.run/vqBX + source: https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-bucket-enforcessl.aws-cdk-bucket-enforcessl + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3';\n...\n" + - pattern: const $X = new Bucket(...) + - pattern-not: "const $X = new Bucket(..., {enforceSSL: true}, ...)\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3';\n...\n" + - pattern: const $X = new $Y.Bucket(...) + - pattern-not: "const $X = new $Y.Bucket(..., {..., enforceSSL: true, ...})\n" + severity: ERROR +- id: typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + languages: + - ts + message: 'Queue $X is missing encryption at rest. Add "encryption: $Y.QueueEncryption.KMS" or "encryption: $Y.QueueEncryption.KMS_MANAGED" + to the queue props to enable encryption at rest for the queue.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-311: Missing Encryption of Sensitive Data' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/sqs-data-protection.html + semgrep.dev: + rule: + origin: community + r_id: 15278 + rule_id: kxUwqO + rv_id: 1263905 + url: + https://semgrep.dev/playground/r/A8Tgd2W/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + version_id: A8Tgd2W + shortlink: https://sg.run/d23P + source: + https://semgrep.dev/r/typescript.aws-cdk.security.audit.awscdk-sqs-unencryptedqueue.awscdk-sqs-unencryptedqueue + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Cryptographic Issues + pattern-either: + - patterns: + - pattern-inside: "import {Queue} from '@aws-cdk/aws-sqs'\n...\n" + - pattern: const $X = new Queue(...) + - pattern-not: "const $X = new Queue(..., {..., encryption: QueueEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new Queue(..., {..., encryption: QueueEncryption.KMS, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-sqs'\n...\n" + - pattern: const $X = new $Y.Queue(...) + - pattern-not: "const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS_MANAGED, ...})\n" + - pattern-not: "const $X = new $Y.Queue(..., {..., encryption: $Y.QueueEncryption.KMS, ...})\n" + severity: WARNING +- id: typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + languages: + - ts + message: Using the GrantPublicAccess method on bucket contruct $X will make the objects in the bucket world + accessible. Verify if this is intentional. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html + semgrep.dev: + rule: + origin: community + r_id: 15279 + rule_id: wdUjZK + rv_id: 1263906 + url: + https://semgrep.dev/playground/r/BjTkZA7/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + version_id: BjTkZA7 + shortlink: https://sg.run/Z4p7 + source: + https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-bucket-grantpublicaccessmethod.awscdk-bucket-grantpublicaccessmethod + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Improper Authentication + pattern-either: + - patterns: + - pattern-inside: "import {Bucket} from '@aws-cdk/aws-s3'\n...\n" + - pattern: "const $X = new Bucket(...)\n...\n$X.grantPublicAccess(...)\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-s3'\n...\n" + - pattern: "const $X = new $Y.Bucket(...)\n...\n$X.grantPublicAccess(...)\n" + severity: WARNING +- id: typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + languages: + - ts + message: CodeBuild Project $X is set to have a public URL. This will make the build results, logs, artifacts + publically accessible, including builds prior to the project being public. Ensure this is acceptable for the + project. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-306: Missing Authentication for Critical Function' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.aws.amazon.com/codebuild/latest/userguide/public-builds.html + semgrep.dev: + rule: + origin: community + r_id: 15280 + rule_id: x8UxXZ + rv_id: 1263907 + url: + https://semgrep.dev/playground/r/DkTRbj1/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + version_id: DkTRbj1 + shortlink: https://sg.run/nK7G + source: + https://semgrep.dev/r/typescript.aws-cdk.security.awscdk-codebuild-project-public.awscdk-codebuild-project-public + subcategory: + - vuln + technology: + - AWS-CDK + vulnerability_class: + - Improper Authentication + pattern-either: + - patterns: + - pattern-inside: "import {Project} from '@aws-cdk/aws-codebuild'\n...\n" + - pattern: "const $X = new Project(..., {..., badge: true, ...})\n" + - patterns: + - pattern-inside: "import * as $Y from '@aws-cdk/aws-codebuild'\n...\n" + - pattern: "const $X = new $Y.Project(..., {..., badge: true, ...})\n" + severity: WARNING +- id: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + languages: + - typescript + - javascript + message: Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to + cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use + dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + semgrep.dev: + rule: + origin: community + r_id: 9769 + rule_id: x8UWvK + rv_id: 1263912 + url: + https://semgrep.dev/playground/r/l4TJR0v/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + version_id: l4TJR0v + shortlink: https://sg.run/rAx6 + source: + https://semgrep.dev/r/typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - focus-metavariable: $X + - pattern-either: + - pattern: "{...,dangerouslySetInnerHTML: {__html: $X},...}\n" + - pattern: "<$Y ... dangerouslySetInnerHTML={{__html: $X}} />\n" + - pattern-not: "<$Y ... dangerouslySetInnerHTML={{__html: \"...\"}} />\n" + - pattern-not: "{...,dangerouslySetInnerHTML:{__html: \"...\"},...}\n" + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: "{...}\n" + - pattern-not: "<... {__html: \"...\"} ...>\n" + - pattern-not: "<... {__html: `...`} ...>\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-not-inside: "$F. ... .$SANITIZEUNC(...)\n" + severity: WARNING +- id: typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + languages: + - typescript + - javascript + message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting + (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization + library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://developer.mozilla.org/en-US/docs/Web/API/Document/writeln + - https://developer.mozilla.org/en-US/docs/Web/API/Document/write + - https://developer.mozilla.org/en-US/docs/Web/API/Element/insertAdjacentHTML + semgrep.dev: + rule: + origin: community + r_id: 9781 + rule_id: QrU68w + rv_id: 1263916 + url: + https://semgrep.dev/playground/r/GxTkeRl/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + version_id: GxTkeRl + shortlink: https://sg.run/E5x8 + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-method.react-unsanitized-method + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "this.window.document. ... .$HTML('...',$SINK) \n" + - pattern: "window.document. ... .$HTML('...',$SINK) \n" + - pattern: "document.$HTML($SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (writeln|write) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: "$PROP. ... .$HTML('...',$SINK) \n" + - metavariable-regex: + metavariable: $HTML + regex: (insertAdjacentHTML) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + severity: WARNING +- id: typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + languages: + - typescript + - javascript + message: Detection of $HTML from non-constant definition. This can inadvertently expose users to cross-site scripting + (XSS) attacks if this comes from user-provided input. If you have to use $HTML, consider using a sanitization + library such as DOMPurify to sanitize your HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://react.dev/reference/react-dom/components/common#dangerously-setting-the-inner-html + semgrep.dev: + rule: + origin: community + r_id: 9782 + rule_id: 3qUBl4 + rv_id: 1263917 + url: + https://semgrep.dev/playground/r/RGT0Lln/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + version_id: RGT0Lln + shortlink: https://sg.run/70Zv + source: https://semgrep.dev/r/typescript.react.security.audit.react-unsanitized-property.react-unsanitized-property + subcategory: + - vuln + technology: + - react + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "import * as $S from \"underscore.string\"\n...\n" + - pattern-inside: "import $S from \"underscore.string\"\n...\n" + - pattern-inside: "$S = require(\"underscore.string\")\n...\n" + - pattern-either: + - pattern: $S.escapeHTML(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from \"dompurify\"\n...\n" + - pattern-inside: "import { ..., $S,... } from \"dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"dompurify\"\n...\n" + - pattern-inside: "$S = require(\"dompurify\")\n...\n" + - pattern-inside: "import $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "import * as $S from \"isomorphic-dompurify\"\n...\n" + - pattern-inside: "$S = require(\"isomorphic-dompurify\")\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "$VALUE = $S(...)\n...\n" + - pattern: $VALUE.sanitize(...) + - patterns: + - pattern-inside: "$VALUE = $S.sanitize\n...\n" + - pattern: $S(...) + - pattern: $S.sanitize(...) + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'xss';\n...\n" + - pattern-inside: "import * as $S from 'xss';\n...\n" + - pattern-inside: "$S = require(\"xss\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "import $S from 'sanitize-html';\n...\n" + - pattern-inside: "import * as $S from \"sanitize-html\";\n...\n" + - pattern-inside: "$S = require(\"sanitize-html\")\n...\n" + - pattern: $S(...) + - patterns: + - pattern-either: + - pattern-inside: "$S = new Remarkable()\n...\n" + - pattern: $S.render(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$BODY = $REACT.useRef(...)\n...\n" + - pattern-inside: "$BODY = useRef(...)\n...\n" + - pattern-inside: "$BODY = findDOMNode(...)\n...\n" + - pattern-inside: "$BODY = createRef(...)\n...\n" + - pattern-inside: "$BODY = $REACT.findDOMNode(...)\n...\n" + - pattern-inside: "$BODY = $REACT.createRef(...)\n...\n" + - pattern-either: + - pattern: "$BODY. ... .$HTML = $SINK \n" + - pattern: "$BODY.$HTML = $SINK \n" + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + - patterns: + - pattern-either: + - pattern: ReactDOM.findDOMNode(...).$HTML = $SINK + - metavariable-regex: + metavariable: $HTML + regex: (innerHTML|outerHTML) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern-either: + - pattern-inside: "function ...({..., $X, ...}) { ... }\n" + - pattern-inside: "function ...(..., $X, ...) { ... }\n" + - focus-metavariable: $X + - pattern-either: + - pattern: $X.$Y + - pattern: $X[...] + severity: WARNING +- id: typescript.react.security.react-insecure-request.react-insecure-request + languages: + - typescript + - javascript + message: Unencrypted request over HTTP detected. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.npmjs.com/package/axios + semgrep.dev: + rule: + origin: community + r_id: 9766 + rule_id: NbUA3O + rv_id: 1263918 + url: + https://semgrep.dev/playground/r/A8Tgd2p/typescript.react.security.react-insecure-request.react-insecure-request + version_id: A8Tgd2p + shortlink: https://sg.run/1n0b + source: https://semgrep.dev/r/typescript.react.security.react-insecure-request.react-insecure-request + subcategory: + - vuln + technology: + - react + vulnerability: Insecure Transport + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern-inside: "import $AXIOS from 'axios';\n...\n$AXIOS.$METHOD(...)\n" + - pattern-inside: "$AXIOS = require('axios');\n...\n$AXIOS.$METHOD(...)\n" + - pattern: $AXIOS.$VERB("$URL",...) + - metavariable-regex: + metavariable: $VERB + regex: ^(get|post|delete|head|patch|put|options) + - patterns: + - pattern-either: + - pattern-inside: "import $AXIOS from 'axios';\n...\n$AXIOS(...)\n" + - pattern-inside: "$AXIOS = require('axios');\n...\n$AXIOS(...)\n" + - pattern-either: + - pattern: '$AXIOS({url: "$URL"}, ...)' + - pattern: "$OPTS = {url: \"$URL\"}\n...\n$AXIOS($OPTS, ...)\n" + - pattern: fetch("$URL", ...) + - metavariable-regex: + metavariable: $URL + regex: ^([Hh][Tt][Tt][Pp]:\/\/(?!localhost).*) + severity: ERROR +- id: yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + languages: + - yaml + message: Using input or workflow parameters in here-scripts can lead to command injection or code injection. Convert + the parameters to env variables instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 – Injection + references: + - https://github.com/argoproj/argo-workflows/issues/5061 + - https://github.com/argoproj/argo-workflows/issues/5114#issue-808865370 + semgrep.dev: + rule: + origin: community + r_id: 40768 + rule_id: 10U0zW + rv_id: 1151472 + url: + https://semgrep.dev/playground/r/xyTp17z/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + version_id: xyTp17z + shortlink: https://sg.run/yqeZ + source: + https://semgrep.dev/r/yaml.argo.security.argo-workflow-parameter-command-injection.argo-workflow-parameter-command-injection + subcategory: + - vuln + technology: + - ci + - argo + vulnerability_class: + - Code Injection + - Command Injection + patterns: + - pattern-inside: "apiVersion: $VERSION\n...\n" + - metavariable-regex: + metavariable: $VERSION + regex: (argoproj.io.*) + - pattern-either: + - patterns: + - pattern-inside: "command:\n ...\n - $LANG\n ...\n...\nsource:\n $SCRIPT\n" + - metavariable-regex: + metavariable: $LANG + regex: + .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $SCRIPT + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $SCRIPT + - patterns: + - pattern-either: + - pattern-inside: "container:\n ...\n command: $LANG\n ...\n args: $PARAM\n" + - pattern-inside: "containerSet:\n ...\n containers:\n - ...\n command: $LANG\n ...\n args: $PARAM\n" + - metavariable-regex: + metavariable: $LANG + regex: + .*(sh|bash|ksh|csh|tcsh|zsh|python|python3|node|perl|ruby|php|lua|awk|sed|powershell|fish|dash|R|grooby|scala|clj|elixir|coffee|dart|haskell|ocaml).* + - metavariable-pattern: + metavariable: $PARAM + pattern-either: + - pattern-regex: (.*{{.*inputs.parameters.*}}.*) + - pattern-regex: (.*{{.*workflow.parameters.*}}.*) + - focus-metavariable: $PARAM + severity: ERROR +- fix: "false\n" + id: yaml.docker-compose.security.privileged-service.privileged-service + languages: + - yaml + message: Service '$SERVICE' is running in privileged mode. This grants the container the equivalent of root + capabilities on the host machine. This can lead to container escapes, privilege escalation, and other security + concerns. Remove the 'privileged' key to disable this capability. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A06:2017 - Security Misconfiguration + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://www.trendmicro.com/en_us/research/19/l/why-running-a-privileged-container-in-docker-is-a-bad-idea.html + - https://containerjournal.com/topics/container-security/why-running-a-privileged-container-is-not-a-good-idea/ + semgrep.dev: + rule: + origin: community + r_id: 10006 + rule_id: DbUW17 + rv_id: 1263922 + url: https://semgrep.dev/playground/r/0bTKzXZ/yaml.docker-compose.security.privileged-service.privileged-service + version_id: 0bTKzXZ + shortlink: https://sg.run/AlX0 + source: https://semgrep.dev/r/yaml.docker-compose.security.privileged-service.privileged-service + subcategory: + - vuln + technology: + - docker-compose + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "version: ...\n...\nservices:\n ...\n $SERVICE:\n ...\n privileged: $TRUE\n" + - focus-metavariable: $TRUE + - metavariable-regex: + metavariable: $TRUE + regex: (true) + severity: WARNING +- id: yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + languages: + - yaml + message: The environment variable `ACTIONS_ALLOW_UNSECURE_COMMANDS` grants this workflow permissions to use the + `set-env` and `add-path` commands. There is a vulnerability in these commands that could result in environment + variables being modified by an attacker. Depending on the use of the environment variable, this could enable an + attacker to, at worst, modify the system path to run a different command than intended, resulting in arbitrary code + execution. This could result in stolen code or secrets. Don't use `ACTIONS_ALLOW_UNSECURE_COMMANDS`. Instead, use + Environment Files. See https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files for more + information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-749: Exposed Dangerous Method or Function' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: A06:2017 - Security Misconfiguration + references: + - https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/ + - https://github.com/actions/toolkit/security/advisories/GHSA-mfwh-5m23-j46w + - https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files + semgrep.dev: + rule: + origin: community + r_id: 13412 + rule_id: EwUQ9x + rv_id: 947039 + url: + https://semgrep.dev/playground/r/jQTzq34/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + version_id: jQTzq34 + shortlink: https://sg.run/qq78 + source: https://semgrep.dev/r/yaml.github-actions.security.allowed-unsecure-commands.allowed-unsecure-commands + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Dangerous Method or Function + patterns: + - pattern-either: + - patterns: + - pattern-inside: '{env: ...}' + - pattern: 'ACTIONS_ALLOW_UNSECURE_COMMANDS: true' + severity: WARNING +- id: yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + languages: + - yaml + message: The Shai-hulud backdoor creates a purposefully vulnerable github action with the name `discussion.yaml`. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-509: Replicating Malicious Code (Virus or Worm)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains + semgrep.dev: + rule: + origin: community + r_id: 238946 + rule_id: 7KUDRPj + rv_id: 1263927 + url: + https://semgrep.dev/playground/r/6xT29ol/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + version_id: 6xT29ol + shortlink: https://sg.run/JdYPZ + source: https://semgrep.dev/r/yaml.github-actions.security.detect-shai-hulud-backdoor.detect-shai-hulud-backdoor + source_rule_url: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Command Injection + paths: + include: + - '**/.github/workflows/discussion.yaml' + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ github.event.issue.title }} + - pattern: ${{ github.event.issue.body }} + - pattern: ${{ github.event.pull_request.title }} + - pattern: ${{ github.event.pull_request.body }} + - pattern: ${{ github.event.comment.body }} + - pattern: ${{ github.event.review.body }} + - pattern: ${{ github.event.review_comment.body }} + - pattern: ${{ github.event.pages. ... .page_name}} + - pattern: ${{ github.event.head_commit.message }} + - pattern: ${{ github.event.head_commit.author.email }} + - pattern: ${{ github.event.head_commit.author.name }} + - pattern: ${{ github.event.commits ... .author.email }} + - pattern: ${{ github.event.commits ... .author.name }} + - pattern: ${{ github.event.pull_request.head.ref }} + - pattern: ${{ github.event.pull_request.head.label }} + - pattern: ${{ github.event.pull_request.head.repo.default_branch }} + - pattern: ${{ github.head_ref }} + - pattern: ${{ github.event.inputs ... }} + - pattern: ${{ github.event.discussion.title }} + - pattern: ${{ github.event.discussion.body }} + - pattern: ${{ inputs ... }} + severity: ERROR +- id: yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + languages: + - yaml + message: A `run:` step pipes the output of `curl` or `wget` directly into a shell interpreter. This is the "curl | + bash" install pattern — if the remote server is compromised or the URL is hijacked, an attacker can execute + arbitrary code in your CI runner. Consider downloading the file first, verifying its checksum or signature, and then + executing it. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A03:2025 - Injection + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions + - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ + semgrep.dev: + rule: + origin: community + r_id: 309392 + rule_id: x8UAgrE + rv_id: 1443456 + url: + https://semgrep.dev/playground/r/9lT3zYb/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + version_id: 9lT3zYb + shortlink: https://sg.run/GR8K1 + source: https://semgrep.dev/r/yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell + subcategory: + - vuln + technology: + - github-actions + - bash + - curl + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: bash + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: curl ... | $CMD ... + - pattern: wget ... | $CMD ... + - metavariable-regex: + metavariable: $CMD + regex: ^(bash|sh|python3?|ruby|perl)$ + severity: ERROR +- id: yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + languages: + - yaml + message: 'A secret is exposed in the workflow-level `env:` block, making it available to every job and step in this workflow + — including any untrusted code run in pull-request workflows. Scope secrets as narrowly as possible: prefer step-level + `env:` so the secret is only available where it is actually needed.' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-secrets + - https://docs.github.com/en/actions/learn-github-actions/variables#defining-environment-variables-for-a-single-workflow + semgrep.dev: + rule: + origin: community + r_id: 309393 + rule_id: OrUnq7z + rv_id: 1443457 + url: + https://semgrep.dev/playground/r/yeTqX9r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + version_id: yeTqX9r + shortlink: https://sg.run/Rrn12 + source: https://semgrep.dev/r/yaml.github-actions.security.gha-workflow-env-secret.gha-workflow-env-secret + subcategory: + - audit + technology: + - github-actions + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "env:\n ...\n" + - pattern-regex: \$\{\{\s*secrets\. + - pattern-not-inside: 'jobs: ...' + severity: WARNING +- id: yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + languages: + - yaml + message: 'GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently repointed by + the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-github-action compromises. Pin + the reference to a full 40-character commit SHA instead, e.g. `uses: actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`.' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-1357: Reliance on Insufficiently Trustworthy Component' + - 'CWE-353: Missing Support for Integrity Check' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions + semgrep.dev: + rule: + origin: community + r_id: 288863 + rule_id: GdUxYDx + rv_id: 1413422 + url: + https://semgrep.dev/playground/r/xyTRDAd/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + version_id: xyTRDAd + shortlink: https://sg.run/2LgAL + source: + https://semgrep.dev/r/yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Cryptographic Issues + - Other + patterns: + - pattern-inside: '{steps: ...}' + - pattern: "uses: \"$ACTION\"\n" + - metavariable-pattern: + language: generic + metavariable: $ACTION + patterns: + - pattern-not-regex: ^\./ + - pattern-not-regex: ^docker:// + - pattern-not-regex: '@[0-9a-f]{40}(\s|$)' + severity: WARNING +- id: yaml.github-actions.security.github-script-injection.github-script-injection + languages: + - yaml + message: "Using variable interpolation `${{...}}` with `github` context data in a `actions/github-script`'s `script:` step + could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code. `github` + context data can have arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment + variable with `env:` to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes + the environment variable, like this: \"$ENVVAR\"." + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + - https://github.com/actions/github-script + semgrep.dev: + rule: + origin: community + r_id: 31441 + rule_id: OrUQvK + rv_id: 1501843 + url: + https://semgrep.dev/playground/r/e1TboJK/yaml.github-actions.security.github-script-injection.github-script-injection + version_id: e1TboJK + shortlink: https://sg.run/g1G0 + source: https://semgrep.dev/r/yaml.github-actions.security.github-script-injection.github-script-injection + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "uses: $ACTION\n...\n" + - pattern-inside: "with:\n ...\n script: ...\n ...\n" + - pattern: 'script: $SHELL' + - metavariable-regex: + metavariable: $ACTION + regex: actions/github-script@.* + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `pull_request_target` and checks out code from the incoming pull + request. When using `pull_request_target`, the Action runs in the context of the target repository, which includes + access to all repository secrets. Normally, this is safe because the Action only runs code from the target + repository, not the incoming PR. However, by checking out the incoming PR code, you're now using the incoming code + for the rest of the action. You may be inadvertently executing arbitrary code from the incoming PR with access to + repository secrets, which would let an attacker steal repository secrets. This normally happens by running build + scripts (e.g., `npm build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit + your workflow file to make sure no code from the incoming PR is executed. Please see + https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software and Data Integrity Failures + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#pull_request_target + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + semgrep.dev: + rule: + origin: community + r_id: 13365 + rule_id: d8Ulkd + rv_id: 1413423 + url: + https://semgrep.dev/playground/r/O9TQ2nX/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + version_id: O9TQ2nX + shortlink: https://sg.run/jkdn + source: + https://semgrep.dev/r/yaml.github-actions.security.pull-request-target-code-checkout.pull-request-target-code-checkout + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Other + patterns: + - pattern-either: + - pattern-inside: "on:\n ...\n pull_request_target: ...\n ...\n...\n" + - pattern-inside: "on: [..., pull_request_target, ...]\n...\n" + - pattern-inside: "on: pull_request_target\n...\n" + - pattern-inside: "jobs:\n ...\n $JOBNAME:\n ...\n steps:\n ...\n" + - pattern: "...\nuses: \"$ACTION\"\nwith:\n ...\n ref: $EXPR\n" + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern-inside: ${{ ... }} + - pattern-either: + - pattern: github.event.pull_request ... + - pattern: github.head_ref ... + severity: ERROR +- id: yaml.github-actions.security.run-shell-injection.run-shell-injection + languages: + - yaml + message: 'Using variable interpolation `${{...}}` with `github` context data in a `run:` step could allow an attacker to + inject their own code into the runner. This would allow them to steal secrets and code. `github` context data can have + arbitrary user input and should be treated as untrusted. Instead, use an intermediate environment variable with `env:` + to store the data and use the environment variable in the `run:` script. Be sure to use double-quotes the environment + variable, like this: "$ENVVAR".' + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections + - https://securitylab.github.com/research/github-actions-untrusted-input/ + semgrep.dev: + rule: + origin: community + r_id: 13162 + rule_id: v8UjQj + rv_id: 1501844 + url: + https://semgrep.dev/playground/r/vdTowy6/yaml.github-actions.security.run-shell-injection.run-shell-injection + version_id: vdTowy6 + shortlink: https://sg.run/pkzk + source: https://semgrep.dev/r/yaml.github-actions.security.run-shell-injection.run-shell-injection + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: 'steps: [...]' + - pattern-inside: "- run: ...\n ...\n" + - pattern: 'run: $SHELL' + - metavariable-pattern: + language: generic + metavariable: $SHELL + patterns: + - pattern-either: + - pattern: ${{ ... github.event.issue.title ... }} + - pattern: ${{ ... github.event.issue.body ... }} + - pattern: ${{ ... github.event.pull_request.title ... }} + - pattern: ${{ ... github.event.pull_request.body ... }} + - pattern: ${{ ... github.event.comment.body ... }} + - pattern: ${{ ... github.event.review.body ... }} + - pattern: ${{ ... github.event.review_comment.body ... }} + - pattern: ${{ ... github.event.pages ... .page_name ... }} + - pattern: ${{ ... github.event.head_commit.message ... }} + - pattern: ${{ ... github.event.head_commit.author.email ... }} + - pattern: ${{ ... github.event.head_commit.author.name ... }} + - pattern: ${{ ... github.event.commits ... .author.email ... }} + - pattern: ${{ ... github.event.commits ... .author.name ... }} + - pattern: ${{ ... github.event.commits ... .message ... }} + - pattern: ${{ ... github.event.pull_request.head.ref ... }} + - pattern: ${{ ... github.event.pull_request.head.label ... }} + - pattern: ${{ ... github.event.pull_request.head.repo.default_branch ... }} + - pattern: ${{ ... github.ref ... }} + - pattern: ${{ ... github.base_ref ... }} + - pattern: ${{ ... github.head_ref ... }} + - pattern: ${{ ... github.ref_name ... }} + - pattern: ${{ ... github.event.inputs ... }} + - pattern: ${{ ... github.event.discussion.title ... }} + - pattern: ${{ ... github.event.discussion.body ... }} + - pattern: ${{ ... github.event.workflow_run.head_branch ... }} + - pattern: ${{ ... github.event.workflow_run.head_commit.message ... }} + - pattern: ${{ ... github.event.milestone.title ... }} + - pattern: ${{ ... github.event.milestone.description ... }} + - pattern: ${{ ... github.event.project_card.note ... }} + - pattern: ${{ ... github.event.project.name ... }} + - pattern: ${{ ... github.event.project_column.name ... }} + - pattern: ${{ ... github.event.release.name ... }} + - pattern: ${{ ... github.event.release.body ... }} + - pattern: ${{ ... github.event.deployment.ref ... }} + - pattern: ${{ ... inputs ... }} + - pattern-not: ${{ ... github.event.issue.title && ... }} + - pattern-not: ${{ ... github.event.issue.body && ... }} + - pattern-not: ${{ ... github.event.pull_request.title && ... }} + - pattern-not: ${{ ... github.event.pull_request.body && ... }} + - pattern-not: ${{ ... github.event.comment.body && ... }} + - pattern-not: ${{ ... github.event.review.body && ... }} + - pattern-not: ${{ ... github.event.review_comment.body && ... }} + - pattern-not: ${{ ... github.event.pages ... .page_name && ... }} + - pattern-not: ${{ ... github.event.head_commit.message && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.email && ... }} + - pattern-not: ${{ ... github.event.head_commit.author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.email && ... }} + - pattern-not: ${{ ... github.event.commits ... .author.name && ... }} + - pattern-not: ${{ ... github.event.commits ... .message && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.ref && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.label && ... }} + - pattern-not: ${{ ... github.event.pull_request.head.repo.default_branch && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_commit.message && ... }} + - pattern-not: ${{ ... github.ref && ... }} + - pattern-not: ${{ ... github.base_ref && ... }} + - pattern-not: ${{ ... github.head_ref && ... }} + - pattern-not: ${{ ... github.ref_name && ... }} + - pattern-not: ${{ ... github.event.inputs && ... }} + - pattern-not: ${{ ... github.event.discussion.title && ... }} + - pattern-not: ${{ ... github.event.discussion.body && ... }} + - pattern-not: ${{ ... github.event.workflow_run.head_branch && ... }} + - pattern-not: ${{ ... github.event.milestone.title && ... }} + - pattern-not: ${{ ... github.event.milestone.description && ... }} + - pattern-not: ${{ ... github.event.project_card.note && ... }} + - pattern-not: ${{ ... github.event.project.name && ... }} + - pattern-not: ${{ ... github.event.project_column.name && ... }} + - pattern-not: ${{ ... github.event.release.name && ... }} + - pattern-not: ${{ ... github.event.release.body && ... }} + - pattern-not: ${{ ... github.event.deployment.ref && ... }} + severity: ERROR +- id: yaml.github-actions.security.secrets-inherit.secrets-inherit + languages: + - yaml + message: "This workflow uses `secrets: inherit` to pass all of the calling workflow's secrets to a reusable workflow. This + violates the principle of least privilege because the called workflow receives access to every secret in the repository, + not just the ones it needs. If the called workflow is compromised or sourced from a third party, an attacker gains access + to all repository secrets. Instead, explicitly pass only the secrets that the called workflow requires using the `secrets:` + map, e.g. `secrets: { MY_SECRET: ${{ secrets.MY_SECRET }} }`." + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://docs.github.com/en/actions/sharing-automations/reusing-workflows#passing-inputs-and-secrets-to-a-reusable-workflow + - https://docs.github.com/en/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions + semgrep.dev: + rule: + origin: community + r_id: 288864 + rule_id: ReUQnKg + rv_id: 1413424 + url: https://semgrep.dev/playground/r/e1T42L1/yaml.github-actions.security.secrets-inherit.secrets-inherit + version_id: e1T42L1 + shortlink: https://sg.run/X2PZB + source: https://semgrep.dev/r/yaml.github-actions.security.secrets-inherit.secrets-inherit + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "jobs:\n ...\n" + - pattern: 'secrets: inherit' + severity: ERROR +- id: yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + languages: + - yaml + message: This GitHub Actions workflow file uses `workflow_run` and checks out code from the incoming pull request. + When using `workflow_run`, the Action runs in the context of the target repository, which includes access to all + repository secrets. Normally, this is safe because the Action only runs code from the target repository, not the + incoming PR. However, by checking out the incoming PR code, you're now using the incoming code for the rest of the + action. You may be inadvertently executing arbitrary code from the incoming PR with access to repository secrets, + which would let an attacker steal repository secrets. This normally happens by running build scripts (e.g., `npm + build` and `make`) or dependency installation scripts (e.g., `python setup.py install`). Audit your workflow file to + make sure no code from the incoming PR is executed. Please see + https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ for additional mitigations. + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-913: Improper Control of Dynamically-Managed Code Resources' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A01:2017 - Injection + references: + - https://securitylab.github.com/research/github-actions-preventing-pwn-requests/ + - https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md + - https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability + semgrep.dev: + rule: + origin: community + r_id: 35494 + rule_id: 4bU8E4 + rv_id: 947046 + url: + https://semgrep.dev/playground/r/kbTYRwl/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + version_id: kbTYRwl + shortlink: https://sg.run/A0p6 + source: + https://semgrep.dev/r/yaml.github-actions.security.workflow-run-target-code-checkout.workflow-run-target-code-checkout + subcategory: + - vuln + technology: + - github-actions + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "on:\n ...\n workflow_run: ...\n ...\n...\n" + - pattern-inside: "jobs:\n ...\n $JOBNAME:\n ...\n steps:\n ...\n" + - pattern: "...\nuses: \"$ACTION\"\nwith:\n ...\n ref: $EXPR\n" + - metavariable-regex: + metavariable: $ACTION + regex: actions/checkout@.* + - metavariable-pattern: + language: generic + metavariable: $EXPR + patterns: + - pattern: ${{ github.event.workflow_run ... }} + severity: WARNING +- fix: "securityContext:\n allowPrivilegeEscalation: false\n$NAME\n" + id: + yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + languages: + - yaml + message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, + certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege + escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a + `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This + will prevent the container from running any privileged processes and limit the impact of any potential attacks. By + adding a `securityContext` to your Kubernetes pod, you can help to ensure that your containerized applications are + more secure and less vulnerable to privilege escalation attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + semgrep.dev: + rule: + origin: community + r_id: 47276 + rule_id: WAU5J6 + rv_id: 1263931 + url: + https://semgrep.dev/playground/r/2KTv2j8/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + version_id: 2KTv2j8 + shortlink: https://sg.run/eleR + source: + https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-no-securitycontext.allow-privilege-escalation-no-securitycontext + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "containers:\n ...\n" + - pattern-inside: "- $NAME: $CONTAINER\n ...\n" + - pattern: "image: ...\n...\n" + - pattern-not: "image: ...\n...\nsecurityContext:\n ...\n" + - metavariable-regex: + metavariable: $NAME + regex: name + - focus-metavariable: $NAME + severity: WARNING +- fix: "false\n" + id: yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + languages: + - yaml + message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, + certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform + privilege escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a + `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This + will prevent the container from running any privileged processes and limit the impact of any potential attacks. In + the container `$CONTAINER` this parameter is set to `true` which makes this container much more vulnerable to + privelege escalation attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + semgrep.dev: + rule: + origin: community + r_id: 47277 + rule_id: 0oUkqQ + rv_id: 1263932 + url: + https://semgrep.dev/playground/r/X0Tzyqr/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + version_id: X0Tzyqr + shortlink: https://sg.run/vw3W + source: + https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation-true.allow-privilege-escalation-true + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "containers:\n ...\n" + - pattern-inside: "- name: $CONTAINER\n ...\n" + - pattern-inside: "image: ...\n...\n" + - pattern-inside: "securityContext:\n ...\n" + - pattern: "allowPrivilegeEscalation: $TRUE\n" + - metavariable-pattern: + metavariable: $TRUE + pattern: "true\n" + - focus-metavariable: $TRUE + severity: WARNING +- fix: "securityContext:\n allowPrivilegeEscalation: false #\n" + id: yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + languages: + - yaml + message: In Kubernetes, each pod runs in its own isolated environment with its own set of security policies. However, + certain container images may contain `setuid` or `setgid` binaries that could allow an attacker to perform privilege + escalation and gain access to sensitive resources. To mitigate this risk, it's recommended to add a + `securityContext` to the container in the pod, with the parameter `allowPrivilegeEscalation` set to `false`. This + will prevent the container from running any privileged processes and limit the impact of any potential attacks. By + adding the `allowPrivilegeEscalation` parameter to your the `securityContext`, you can help to ensure that your + containerized applications are more secure and less vulnerable to privilege escalation attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-732: Incorrect Permission Assignment for Critical Resource' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#privilege-escalation + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + - https://www.kernel.org/doc/Documentation/prctl/no_new_privs.txt + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-4-add-no-new-privileges-flag + semgrep.dev: + rule: + origin: community + r_id: 10057 + rule_id: 6JUqEO + rv_id: 1263933 + url: + https://semgrep.dev/playground/r/jQTn527/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + version_id: jQTn527 + shortlink: https://sg.run/ljp6 + source: https://semgrep.dev/r/yaml.kubernetes.security.allow-privilege-escalation.allow-privilege-escalation + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "containers:\n ...\n" + - pattern-inside: "- name: $CONTAINER\n ...\n" + - pattern: "image: ...\n...\n" + - pattern-inside: "image: ...\n...\n$SC:\n ...\n" + - metavariable-regex: + metavariable: $SC + regex: ^(securityContext)$ + - pattern-not-inside: "image: ...\n...\nsecurityContext:\n ...\n allowPrivilegeEscalation: $VAL\n" + - focus-metavariable: $SC + severity: WARNING +- id: yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + languages: + - yaml + message: 'Semgrep detected a Kubernetes core API ClusterRole with excessive permissions. Attaching excessive permissions + to a ClusterRole associated with the core namespace allows the V1 API to perform arbitrary actions on arbitrary resources + attached to the cluster. Prefer explicit allowlists of verbs/resources when configuring the core API namespace. ' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-269: Improper Privilege Management' + cwe2021-top25: false + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/docs/reference/access-authn-authz/rbac/#role-and-clusterrole + - https://kubernetes.io/docs/concepts/security/rbac-good-practices/#general-good-practice + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.28/#api-groups + semgrep.dev: + rule: + origin: community + r_id: 73474 + rule_id: GdUR2A + rv_id: 1263935 + url: + https://semgrep.dev/playground/r/9lT4bw7/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + version_id: 9lT4bw7 + shortlink: https://sg.run/x6Dz + source: + https://semgrep.dev/r/yaml.kubernetes.security.legacy-api-clusterrole-excessive-permissions.legacy-api-clusterrole-excessive-permissions + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern: "\"*\"\n" + - pattern-inside: "resources: $A\n...\n" + - pattern-inside: "verbs: $A\n...\n" + - pattern-inside: "- apiGroups: [\"\"]\n ...\n" + - pattern-inside: "apiVersion: rbac.authorization.k8s.io/v1\n...\n" + - pattern-inside: "kind: ClusterRole\n...\n" + severity: WARNING +- fix: "true\n" + id: yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + languages: + - yaml + message: When running containers in Kubernetes, it's important to ensure that they are properly secured to prevent + privilege escalation attacks. One potential vulnerability is when a container is allowed to run applications as + the root user, which could allow an attacker to gain access to sensitive resources. To mitigate this risk, it's + recommended to add a `securityContext` to the container, with the parameter `runAsNonRoot` set to `true`. This + will ensure that the container runs as a non-root user, limiting the damage that could be caused by any potential + attacks. By adding a `securityContext` to the container in your Kubernetes pod, you can help to ensure that your + containerized applications are more secure and less vulnerable to privilege escalation attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-250: Execution with Unnecessary Privileges' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2021 - Security Misconfiguration + - A06:2017 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://kubernetes.io/blog/2016/08/security-best-practices-kubernetes-deployment/ + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/ + - https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html#rule-2-set-a-user + semgrep.dev: + rule: + origin: community + r_id: 26096 + rule_id: L1UAxy + rv_id: 1263939 + url: + https://semgrep.dev/playground/r/NdTzyj8/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + version_id: NdTzyj8 + shortlink: https://sg.run/D9No + source: https://semgrep.dev/r/yaml.kubernetes.security.run-as-non-root-unsafe-value.run-as-non-root-unsafe-value + subcategory: + - audit + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern-either: + - pattern: "spec:\n ...\n securityContext:\n ...\n runAsNonRoot: $VALUE\n" + - patterns: + - pattern-inside: "containers:\n ...\n" + - pattern: "image: ...\n...\nsecurityContext:\n ...\n runAsNonRoot: $VALUE\n" + - metavariable-pattern: + metavariable: $VALUE + pattern: "false\n" + - focus-metavariable: $VALUE + severity: INFO +- id: yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + languages: + - yaml + message: "Container is explicitly disabling seccomp confinement. This runs the service in an unrestricted state. Remove + 'seccompProfile: unconfined' to prevent this." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-284: Improper Access Control' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://kubernetes.io/docs/concepts/policy/pod-security-policy/#seccomp + - https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ + semgrep.dev: + rule: + origin: community + r_id: 10059 + rule_id: zdUynw + rv_id: 1263941 + url: + https://semgrep.dev/playground/r/w8TRoL3/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + version_id: w8TRoL3 + shortlink: https://sg.run/6rgY + source: https://semgrep.dev/r/yaml.kubernetes.security.seccomp-confinement-disabled.seccomp-confinement-disabled + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: "containers:\n ...\n" + - pattern: "image: ...\n...\nsecurityContext:\n ...\n seccompProfile: unconfined\n" + severity: WARNING +- id: yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + languages: + - yaml + message: 'Secrets ($VALUE) should not be stored in infrastructure as code files. Use an alternative such as Bitnami Sealed + Secrets or KSOPS to encrypt Kubernetes Secrets. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://kubernetes.io/docs/concepts/configuration/secret/ + - https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/0/CTR_Kubernetes_Hardening_Guidance_1.1_20220315.PDF + - https://docs.gitlab.com/ee/user/clusters/agent/gitops/secrets_management.html + - https://www.cncf.io/blog/2021/04/22/revealing-the-secrets-of-kubernetes-secrets/ + - https://github.com/bitnami-labs/sealed-secrets + - https://www.cncf.io/blog/2022/01/25/secrets-management-essential-when-using-kubernetes/ + - https://blog.oddbit.com/post/2021-03-09-getting-started-with-ksops/ + semgrep.dev: + rule: + origin: community + r_id: 20055 + rule_id: YGUYEb + rv_id: 1263942 + url: + https://semgrep.dev/playground/r/xyTjz5B/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + version_id: xyTjz5B + shortlink: https://sg.run/KyL6 + source: https://semgrep.dev/r/yaml.kubernetes.security.secrets-in-config-file.secrets-in-config-file + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Hard-coded Secrets + patterns: + - pattern: "$KEY: $VALUE\n" + - pattern-inside: "data: ...\n" + - pattern-inside: "kind: Secret\n...\n" + - metavariable-regex: + metavariable: $VALUE + regex: (?i)^[aA-zZ0-9+/]+={0,2}$ + - metavariable-analysis: + analyzer: entropy + metavariable: $VALUE + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + languages: + - yaml + message: "Cluster is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections + insecure. Remove the 'insecure-skip-tls-verify: true' key to secure communication." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://kubernetes.io/docs/reference/config-api/client-authentication.v1beta1/#client-authentication-k8s-io-v1beta1-Cluster + semgrep.dev: + rule: + origin: community + r_id: 10116 + rule_id: zdUyWx + rv_id: 1263943 + url: + https://semgrep.dev/playground/r/O9Tpxbo/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + version_id: O9Tpxbo + shortlink: https://sg.run/okyn + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-cluster.skip-tls-verify-cluster + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Mishandled Sensitive Information + pattern: "cluster:\n ...\n insecure-skip-tls-verify: true\n" + severity: WARNING +- id: yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + languages: + - yaml + message: "Service is disabling TLS certificate verification when communicating with the server. This makes your HTTPS connections + insecure. Remove the 'insecureSkipTLSVerify: true' key to secure communication." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#apiservice-v1-apiregistration-k8s-io + semgrep.dev: + rule: + origin: community + r_id: 10117 + rule_id: pKUGXr + rv_id: 1263944 + url: + https://semgrep.dev/playground/r/e1TyjnR/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + version_id: e1TyjnR + shortlink: https://sg.run/zk10 + source: https://semgrep.dev/r/yaml.kubernetes.security.skip-tls-verify-service.skip-tls-verify-service + subcategory: + - vuln + technology: + - kubernetes + vulnerability_class: + - Mishandled Sensitive Information + pattern: "spec:\n ...\n insecureSkipTLSVerify: true\n" + severity: WARNING +- id: yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + languages: + - yaml + message: "Found 'x-openai-isConsequential: false' in a state-changing HTTP method: $METHOD $PATH. This Action configuration + will enable the 'Always Allow' option for state-changing HTTP methods, such as POST, PUT, PATCH, or DELETE. The risk of + a user selecting the 'Always Allow' button is that the agent could perform unintended actions on behalf of the user. When + working with sensitive functionality, it is always best to include a Human In The Loop (HITL) type of control. Consider + the trade-off between security and user friction and then make a risk-based decision about this function." + metadata: + category: security + confidence: HIGH + cwe: "CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A04:2021 Insecure Design + - LLM08:2023 - Excessive Agency + references: + - https://platform.openai.com/docs/actions/consequential-flag + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/www-project-top-10-for-large-language-model-applications/assets/PDF/OWASP-Top-10-for-LLMs-2023-v1_1.pdf + semgrep.dev: + rule: + origin: community + r_id: 146574 + rule_id: yyURooD + rv_id: 947071 + url: + https://semgrep.dev/playground/r/WrTEZN8/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + version_id: WrTEZN8 + shortlink: https://sg.run/x8EEP + source: + https://semgrep.dev/r/yaml.openapi.security.openai-consequential-action-false.openai-consequential-action-false + subcategory: + - audit + technology: + - openapi + - openai + vulnerability_class: + - Server-Side Request Forgery (SSRF) + pattern-either: + - pattern-inside: "post:\n ...\n x-openai-isConsequential: false\n" + - pattern-inside: "put:\n ...\n x-openai-isConsequential: false\n" + - pattern-inside: "patch:\n ...\n x-openai-isConsequential: false\n" + - pattern-inside: "delete:\n ...\n x-openai-isConsequential: false\n" + severity: WARNING +- id: yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + languages: + - yaml + message: Basic authentication is considered weak and should be avoided. Use a different authentication scheme, such + of OAuth2, OpenID Connect, or mTLS. + metadata: + category: security + confidence: HIGH + cwe: 'CWE-287: Improper Authentication' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 Insecure Design + - A07:2021 Identification and Authentication Failures + references: + - https://cwe.mitre.org/data/definitions/287.html + - https://owasp.org/Top10/A04_2021-Insecure_Design/ + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures/ + semgrep.dev: + rule: + origin: community + r_id: 133077 + rule_id: zdUKgEX + rv_id: 947072 + url: + https://semgrep.dev/playground/r/0bT1ErG/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + version_id: 0bT1ErG + shortlink: https://sg.run/v8wNW + source: https://semgrep.dev/r/yaml.openapi.security.use-of-basic-authentication.use-of-basic-authentication + subcategory: + - vuln + technology: + - openapi + vulnerability_class: + - Improper Authentication + patterns: + - pattern-inside: "openapi: $VERSION\n...\ncomponents:\n ...\n securitySchemes:\n ...\n $SCHEME:\n ...\n" + - metavariable-regex: + metavariable: $VERSION + regex: 3.* + - pattern: "type: http\n...\nscheme: basic\n" + severity: ERROR diff --git a/.semgrep/registry/package-managers.yaml b/.semgrep/registry/package-managers.yaml new file mode 100644 index 0000000..a828597 --- /dev/null +++ b/.semgrep/registry/package-managers.yaml @@ -0,0 +1,429 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age, r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown, r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age, r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate, r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age, r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age, r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + languages: + - generic + message: 'This bunfig.toml does not set a minimum release age or sets it too low. Newly published packages can be malicious + or unstable. Add `minimumReleaseAge = 604800` under the `[install]` section to wait 7 days before resolving newly published + package versions. Added in: v1.3 Reference: https://bun.sh/docs/runtime/bunfig' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://bun.sh/docs/runtime/bunfig + semgrep.dev: + rule: + origin: community + r_id: 291646 + rule_id: oqUyJOb + rv_id: 1423385 + url: + https://semgrep.dev/playground/r/BjTyRe5/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + version_id: BjTyRe5 + shortlink: https://sg.run/JqPrR + source: https://semgrep.dev/r/package_managers.bun.bun-missing-minimum-release-age.bun-missing-minimum-release-age + subcategory: + - audit + technology: + - bun + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/bunfig.toml' + - '**/.bunfig.toml' + pattern-either: + - patterns: + - pattern-regex: (?ms)\[install\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*minimumReleaseAge) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: minimumReleaseAge\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 604800 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)minimumReleaseAge[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)minimumReleaseAge\s*=\s*$ + severity: MEDIUM +- id: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + languages: + - yaml + message: 'This Dependabot configuration does not set a cooldown period. Newly published packages can be malicious or unstable. + Add a `cooldown` block with `default-days: 7` to each `package-ecosystem` entry under `updates` to wait 7 days before + proposing updates to newly published package versions. Reference: https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#cooldown + semgrep.dev: + rule: + origin: community + r_id: 291647 + rule_id: zdUArOL + rv_id: 1423386 + url: + https://semgrep.dev/playground/r/DkTwEGl/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + version_id: DkTwEGl + shortlink: https://sg.run/5WvGK + source: https://semgrep.dev/r/package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown + subcategory: + - audit + technology: + - dependabot + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.github/dependabot.yml' + - '**/.github/dependabot.yaml' + pattern-either: + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern: "- package-ecosystem: $ECOSYSTEM\n ...\n" + - pattern-not: "- package-ecosystem: $ECOSYSTEM\n ...\n cooldown:\n ...\n ...\n" + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern-regex: default-days\s*:\s*(?P\d+) + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-inside: "updates:\n ...\n" + - pattern: "cooldown:\n default-days: $DAYS\n" + - metavariable-regex: + metavariable: $DAYS + regex: ^\D + - focus-metavariable: $DAYS + severity: MEDIUM +- id: package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + languages: + - generic + message: 'This .npmrc does not set a minimum release age or sets it too low. Newly published packages can be malicious or + unstable. Add `min-release-age = 7` to wait 7 days before resolving newly published package versions. Added in: v11.10 + Reference: https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://github.blog/changelog/2026-02-18-npm-bulk-trusted-publishing-config-and-script-security-now-generally-available/ + - https://github.com/npm/cli/pull/8965 + semgrep.dev: + rule: + origin: community + r_id: 291648 + rule_id: pKU6A82 + rv_id: 1423387 + url: + https://semgrep.dev/playground/r/WrT7LdL/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + version_id: WrT7LdL + shortlink: https://sg.run/GRo1z + source: https://semgrep.dev/r/package_managers.npm.npm-missing-minimum-release-age.npm-missing-minimum-release-age + subcategory: + - audit + technology: + - npm + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.npmrc' + pattern-either: + - patterns: + - pattern-regex: (?:(?:^---\n)(?:[^\n]*\n)|^)(?P(?:(?!\n---)[\s\S])*\S(?:(?!\n---)[\s\S])*) + - pattern-not-regex: min-release-age + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: min-release-age\s*=\s*\d+ + - pattern-regex: =\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 7 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)min-release-age[ \t]*=[ \t]*(?P[^\s\d][^\n]*) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)min-release-age\s*=\s*$ + severity: MEDIUM +- id: package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + languages: + - yaml + message: 'This pnpm workspace configuration does not set a minimum release age. Newly published packages can be malicious + or unstable. Add `minimumReleaseAge: 10080` (minutes) to wait at least seven days before installing newly published package + versions. Added in: v10.16.0 Reference: https://pnpm.io/settings#minimumreleaseage' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://pnpm.io/settings#minimumreleaseage + semgrep.dev: + rule: + origin: community + r_id: 291650 + rule_id: X5Uwn1n + rv_id: 1423389 + url: + https://semgrep.dev/playground/r/K3TgxrW/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + version_id: K3TgxrW + shortlink: https://sg.run/Aj0o0 + source: https://semgrep.dev/r/package_managers.pnpm.pnpm-missing-minimum-release-age.pnpm-minimum-release-age + subcategory: + - audit + technology: + - pnpm + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pnpm-workspace.yaml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?P^(?:packages|catalog)\s*:)(?:(?!^minimumReleaseAge\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: ^\s*minimumReleaseAge\s*:\s*(?P\d+) + - metavariable-comparison: + comparison: int($AGE) < 10080 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern: "minimumReleaseAge: $AGE\n" + - metavariable-regex: + metavariable: $AGE + regex: ^\D + - focus-metavariable: $AGE + - patterns: + - pattern-regex: (?m)^\s*minimumReleaseAge\s*:\s*$ + severity: MEDIUM +- id: package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + languages: + - json + message: 'This Renovate configuration does not set a minimum release age. Newly published packages can be malicious or unstable. + Add `"minimumReleaseAge": "7 days"` within a `packageRules` entry to wait 7 days before proposing updates to newly published + package versions. Set `"minimumReleaseAge": false` to set an exception for minimal release age for the package rule. Added + in: v42' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.renovatebot.com/configuration-options/#minimumreleaseage + semgrep.dev: + rule: + origin: community + r_id: 291652 + rule_id: 10UbQrX + rv_id: 1443454 + url: + https://semgrep.dev/playground/r/jQT1KAX/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + version_id: jQT1KAX + shortlink: https://sg.run/D8l2q + source: + https://semgrep.dev/r/package_managers.renovate.renovate-missing-minimum-release-age.renovate-missing-minimum-release-age + subcategory: + - audit + technology: + - renovate + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/renovate.json' + - '**/renovate.json5' + - '**/.renovaterc' + - '**/.renovaterc.json' + - '**/.renovaterc.json5' + pattern-either: + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern-either: + - pattern: "{ ..., \"matchPackageNames\": [...], ... }\n" + - pattern: "{ ..., \"matchPackagePatterns\": [...], ... }\n" + - pattern: "{ ..., \"matchDepTypes\": [...], ... }\n" + - pattern-not: "{\n ...,\n \"minimumReleaseAge\": $AGE,\n ...\n}\n" + - pattern-not: "{\n ...,\n \"minimumReleaseAge\": false,\n ...\n}\n" + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern-regex: '"minimumReleaseAge":\s*"(?P\d+) days?"' + - metavariable-comparison: + comparison: int($AGE) < 7 + metavariable: $AGE + - focus-metavariable: $AGE + - patterns: + - pattern-inside: "\"packageRules\": [\n ...\n]\n" + - pattern: "\"minimumReleaseAge\": \"$AGE\"\n" + - metavariable-regex: + metavariable: $AGE + regex: ^(?!\d+ days?$) + - focus-metavariable: $AGE + severity: MEDIUM +- id: package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + languages: + - generic + message: 'This pyproject.toml configures uv but does not set a dependency cooldown. Newly published packages can be malicious + or unstable. Add `exclude-newer = "7 days"` under `[tool.uv]` to wait 7 days before resolving newly published package + versions. Added in: 0.9.17 Reference: https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://docs.astral.sh/uv/concepts/resolution/#dependency-cooldowns + semgrep.dev: + rule: + origin: community + r_id: 291653 + rule_id: 9AUo6vE + rv_id: 1501839 + url: + https://semgrep.dev/playground/r/kbT3B1J/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + version_id: kbT3B1J + shortlink: https://sg.run/WeY0Z + source: https://semgrep.dev/r/package_managers.uv.uv-missing-dependency-cooldown.uv-missing-dependency-cooldown + subcategory: + - audit + technology: + - uv + - python + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/pyproject.toml' + - '**/uv.toml' + pattern-either: + - patterns: + - pattern-regex: (?ms)\[tool\.uv\](?P[^\[]*?)(?=\[|\z) + - metavariable-regex: + metavariable: $TARGET + regex: ^(?![\s\S]*exclude-newer) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P\d+)\s*d(?:ays?)?" + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: exclude-newer\s*=\s*"(?P[^"]+)" + - metavariable-regex: + metavariable: $VAL + regex: + (?i)^(?!\d+\s*d(?:ays?)?\b)(?!\d+\s*(?:weeks?|wks?|w|months?|mos?|mo|years?|yrs?|y)\b)(?!P[^Tt]*[WMY])(?!P(?:[7-9]|[1-9]\d+)D\b) + - focus-metavariable: $VAL + severity: MEDIUM +- id: package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + languages: + - yaml + message: 'This .yarnrc.yml does not set a minimal age gate or sets it too low. Newly published packages can be malicious + or unstable. Add `npmMinimalAgeGate: "7d"` to wait 7 days before resolving newly published package versions. Added in: + 4.10 Reference: https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-829: Inclusion of Functionality from Untrusted Control Sphere' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2021 - Software and Data Integrity Failures + references: + - https://yarnpkg.com/configuration/yarnrc#npmMinimalAgeGate + semgrep.dev: + rule: + origin: community + r_id: 291654 + rule_id: yyUBeEz + rv_id: 1423393 + url: + https://semgrep.dev/playground/r/JdTnXlj/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + version_id: JdTnXlj + shortlink: https://sg.run/0gvNq + source: https://semgrep.dev/r/package_managers.yarn.yarn-missing-minimal-age-gate.yarn-missing-minimal-age-gate + subcategory: + - audit + technology: + - yarn + - javascript + vulnerability_class: + - Insecure Configuration + paths: + include: + - '**/.yarnrc.yml' + pattern-either: + - patterns: + - pattern-regex: + (?ms)(?:\A|^---$\n)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?P^(?:nodeLinker|yarnPath|enableGlobalCache|npmScopes|npmRegistryServer)\s*:)(?:(?!^npmMinimalAgeGate\s*:)(?!^---$)[\s\S])*?(?=^---$|\z) + - focus-metavariable: $TARGET + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate\s*:\s*['"]?(?P\d+)d['"]? + - metavariable-comparison: + comparison: int($DAYS) < 7 + metavariable: $DAYS + - focus-metavariable: $DAYS + - patterns: + - pattern-regex: (?m)npmMinimalAgeGate[ \t]*:[ \t]*(?P\S+) + - metavariable-regex: + metavariable: $VAL + regex: ^(?!['"]?\d+d['"]?$) + - focus-metavariable: $VAL + - patterns: + - pattern-regex: (?m)^npmMinimalAgeGate\s*:\s*$ + severity: MEDIUM diff --git a/.semgrep/registry/python.yaml b/.semgrep/registry/python.yaml new file mode 100644 index 0000000..453e5ef --- /dev/null +++ b/.semgrep/registry/python.yaml @@ -0,0 +1,10215 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/python +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + languages: + - python + message: Detected 'create_subprocess_exec' function with argument tainted by `event` object. If this data can be + controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it + is not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html#asyncio.create_subprocess_exec + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18260 + rule_id: EwUrX8 + rv_id: 1263331 + url: + https://semgrep.dev/playground/r/rxTAKgo/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + version_id: rxTAKgo + shortlink: https://sg.run/oyv0 + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-create-exec.dangerous-asyncio-create-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: asyncio.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, [$CMD, ...], ...) + - pattern: asyncio.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: asyncio.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: asyncio.subprocess.create_subprocess_exec($PROG, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], + ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + languages: + - python + message: Detected subprocess function '$LOOP.subprocess_exec' with argument tainted by `event` object. If this data + can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to + ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18261 + rule_id: 7KUxXg + rv_id: 1263332 + url: + https://semgrep.dev/playground/r/bZT53Ww/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + version_id: bZT53Ww + shortlink: https://sg.run/z14d + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-exec.dangerous-asyncio-exec + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_exec($PROTOCOL, $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, [$CMD, ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", $CMD, ...], ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + languages: + - python + message: Detected asyncio subprocess function with argument tainted by `event` object. If this data can be controlled + by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not + controllable by an external resource. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18262 + rule_id: L1UEl7 + rv_id: 1263333 + url: + https://semgrep.dev/playground/r/NdTzyWA/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + version_id: NdTzyWA + shortlink: https://sg.run/p9vZ + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-asyncio-shell.dangerous-asyncio-shell + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern: asyncio.create_subprocess_shell($CMD, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + languages: + - python + message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach + this function call because it allows a malicious actor to execute commands. Ensure no external data reaches here. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18263 + rule_id: 8GUGBq + rv_id: 1263334 + url: + https://semgrep.dev/playground/r/kbTzGv8/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + version_id: kbTzGv8 + shortlink: https://sg.run/2AjL + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-spawn-process.dangerous-spawn-process + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - patterns: + - pattern: os.$METHOD($MODE, $CMD, ...) + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c", $CMD,...],...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + languages: + - python + message: Detected subprocess function with argument tainted by an `event` object. If this data can be controlled by a + malicious actor, it may be an instance of command injection. The default option for `shell` is False, and this is + secure by default. Consider removing the `shell=True` or setting it to False explicitely. Using `shell=False` means + you have to split the command string into an array of strings for the command and its arguments. You may consider + using 'shlex.split()' for this purpose. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + semgrep.dev: + rule: + origin: community + r_id: 18264 + rule_id: gxUyn1 + rv_id: 1263335 + url: + https://semgrep.dev/playground/r/w8TRogj/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + version_id: w8TRogj + shortlink: https://sg.run/XZ7B + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-subprocess-use.dangerous-subprocess-use + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - Command Injection + mode: taint + pattern-sanitizers: + - pattern: shlex.split(...) + - pattern: pipes.quote(...) + - pattern: shlex.quote(...) + pattern-sinks: + - patterns: + - pattern: subprocess.$FUNC(..., shell=True, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dangerous-system-call.dangerous-system-call + languages: + - python + message: Detected `os` function with argument tainted by `event` object. This is dangerous if external data can reach + this function call because it allows a malicious actor to execute commands. Use the 'subprocess' module instead, + which is easier to use without accidentally exposing a command injection vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18265 + rule_id: QrUkg6 + rv_id: 1263336 + url: + https://semgrep.dev/playground/r/xyTjzbG/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + version_id: xyTjzbG + shortlink: https://sg.run/jDvN + source: https://semgrep.dev/r/python.aws-lambda.security.dangerous-system-call.dangerous-system-call + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $CMD + - pattern-either: + - pattern: os.system($CMD,...) + - pattern: os.popen($CMD,...) + - pattern: os.popen2($CMD,...) + - pattern: os.popen3($CMD,...) + - pattern: os.popen4($CMD,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + languages: + - python + message: Detected DynamoDB query filter that is tainted by `$EVENT` object. This could lead to NoSQL injection if the + variable is user-controlled and not properly sanitized. Explicitly assign query params instead of passing data from + `$EVENT` directly to DynamoDB client. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-943: Improper Neutralization of Special Elements in Data Query Logic' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + references: + - https://medium.com/appsecengineer/dynamodb-injection-1db99c2454ac + semgrep.dev: + rule: + origin: community + r_id: 21321 + rule_id: KxUJ2B + rv_id: 946088 + url: + https://semgrep.dev/playground/r/9lTy1rQ/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + version_id: 9lTy1rQ + shortlink: https://sg.run/jjrl + source: https://semgrep.dev/r/python.aws-lambda.security.dynamodb-filter-injection.dynamodb-filter-injection + subcategory: + - vuln + technology: + - python + - boto3 + - aws-lambda + - dynamodb + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - patterns: + - pattern: "{...}\n" + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: $TABLE.scan(..., ScanFilter = $SINK, ...) + - pattern: $TABLE.query(..., QueryFilter = $SINK, ...) + - pattern-either: + - patterns: + - pattern-inside: "$TABLE = $DB.Table(...)\n...\n" + - pattern-inside: "$DB = boto3.resource('dynamodb', ...)\n...\n" + - pattern-inside: "$TABLE = boto3.client('dynamodb', ...)\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.aws-lambda.security.mysql-sqli.mysql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', ('active'))`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-execute.html + - https://dev.mysql.com/doc/connector-python/en/connector-python-api-mysqlcursor-executemany.html + semgrep.dev: + rule: + origin: community + r_id: 18266 + rule_id: 3qU3eE + rv_id: 1263337 + url: https://semgrep.dev/playground/r/O9TpxLJ/python.aws-lambda.security.mysql-sqli.mysql-sqli + version_id: O9TpxLJ + shortlink: https://sg.run/1RjG + source: https://semgrep.dev/r/python.aws-lambda.security.mysql-sqli.mysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - mysql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern-either: + - pattern-inside: "import mysql\n...\n" + - pattern-inside: "import mysql.cursors\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.psycopg-sqli.psycopg-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.psycopg.org/docs/cursor.html#cursor.execute + - https://www.psycopg.org/docs/cursor.html#cursor.executemany + - https://www.psycopg.org/docs/cursor.html#cursor.mogrify + semgrep.dev: + rule: + origin: community + r_id: 18267 + rule_id: 4bUQG1 + rv_id: 1263338 + url: https://semgrep.dev/playground/r/e1TyjPZ/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + version_id: e1TyjPZ + shortlink: https://sg.run/9L8r + source: https://semgrep.dev/r/python.aws-lambda.security.psycopg-sqli.psycopg-sqli + subcategory: + - vuln + technology: + - aws-lambda + - psycopg + - psycopg2 + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern-either: + - pattern: $CURSOR.execute($QUERY,...) + - pattern: $CURSOR.executemany($QUERY,...) + - pattern: $CURSOR.mogrify($QUERY,...) + - pattern-inside: "import psycopg2\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.pymssql-sqli.pymssql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pypi.org/project/pymssql/ + semgrep.dev: + rule: + origin: community + r_id: 18268 + rule_id: PeUxO0 + rv_id: 1263339 + url: https://semgrep.dev/playground/r/vdT06bG/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + version_id: vdT06bG + shortlink: https://sg.run/yXvP + source: https://semgrep.dev/r/python.aws-lambda.security.pymssql-sqli.pymssql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - pymssql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: "import pymssql\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.pymysql-sqli.pymysql-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = %s', ('active'))`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://pypi.org/project/PyMySQL/#id4 + semgrep.dev: + rule: + origin: community + r_id: 18269 + rule_id: JDUlel + rv_id: 1263340 + url: https://semgrep.dev/playground/r/d6TyxNA/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + version_id: d6TyxNA + shortlink: https://sg.run/reve + source: https://semgrep.dev/r/python.aws-lambda.security.pymysql-sqli.pymysql-sqli + subcategory: + - vuln + technology: + - aws-lambda + - pymysql + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-either: + - pattern-inside: "import pymysql\n...\n" + - pattern-inside: "import pymysql.cursors\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + languages: + - python + message: "Detected SQL statement that is tainted by `event` object. This could lead to SQL injection if the variable is + user-controlled and not properly sanitized. In order to prevent SQL injection, use parameterized queries or prepared statements + instead. You can use parameterized statements like so: `cursor.execute('SELECT * FROM projects WHERE status = ?', 'active')`" + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/connections.html#sqlalchemy.engine.Connection.execute + semgrep.dev: + rule: + origin: community + r_id: 18270 + rule_id: 5rUy3N + rv_id: 1263341 + url: https://semgrep.dev/playground/r/ZRTKARp/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + version_id: ZRTKARp + shortlink: https://sg.run/b48W + source: https://semgrep.dev/r/python.aws-lambda.security.sqlalchemy-sqli.sqlalchemy-sqli + subcategory: + - vuln + technology: + - aws-lambda + - sqlalchemy + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $QUERY + - pattern: $CURSOR.execute($QUERY,...) + - pattern-inside: "import sqlalchemy\n...\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-code-exec.tainted-code-exec + languages: + - python + message: Detected the use of `exec/eval`.This can be dangerous if used to evaluate dynamic content. If this content + can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not + definable by external sources. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18271 + rule_id: GdUDJP + rv_id: 1263342 + url: https://semgrep.dev/playground/r/nWT2LD2/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + version_id: nWT2LD2 + shortlink: https://sg.run/Ng7y + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-code-exec.tainted-code-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: eval($CODE, ...) + - pattern: exec($CODE, ...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-html-response.tainted-html-response + languages: + - python + message: Detected user input flowing into an HTML response. You may be accidentally bypassing secure methods of + rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, which could + let attackers steal sensitive user data. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18272 + rule_id: ReUKrk + rv_id: 1263343 + url: + https://semgrep.dev/playground/r/ExTEx5o/python.aws-lambda.security.tainted-html-response.tainted-html-response + version_id: ExTEx5o + shortlink: https://sg.run/k9vP + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-response.tainted-html-response + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern: $BODY + - pattern-inside: "{..., \"headers\": {..., \"Content-Type\": \"text/html\", ...}, \"body\": $BODY, ... }\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-html-string.tainted-html-string + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 18484 + rule_id: JDUlwy + rv_id: 1263344 + url: https://semgrep.dev/playground/r/7ZTE36K/python.aws-lambda.security.tainted-html-string.tainted-html-string + version_id: 7ZTE36K + shortlink: https://sg.run/8zNy + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-html-string.tainted-html-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + - pattern-not-inside: "print(...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + languages: + - python + message: Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the + serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON + or a similar text-based serialization format. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + - https://davidhamann.de/2020/04/05/exploiting-python-pickle/ + semgrep.dev: + rule: + origin: community + r_id: 21602 + rule_id: JDUDQg + rv_id: 1263345 + url: + https://semgrep.dev/playground/r/LjTkgd9/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + version_id: LjTkgd9 + shortlink: https://sg.run/JbjW + source: + https://semgrep.dev/r/python.aws-lambda.security.tainted-pickle-deserialization.tainted-pickle-deserialization + subcategory: + - vuln + technology: + - python + - aws-lambda + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - patterns: + - focus-metavariable: $SINK + - pattern-either: + - pattern: pickle.load($SINK,...) + - pattern: pickle.loads($SINK,...) + - pattern: _pickle.load($SINK,...) + - pattern: _pickle.loads($SINK,...) + - pattern: cPickle.load($SINK,...) + - pattern: cPickle.loads($SINK,...) + - pattern: dill.load($SINK,...) + - pattern: dill.loads($SINK,...) + - pattern: shelve.open($SINK,...) + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: WARNING +- id: python.aws-lambda.security.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as Sequelize which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/SQL_Injection + semgrep.dev: + rule: + origin: community + r_id: 18273 + rule_id: AbU3LX + rv_id: 1263346 + url: https://semgrep.dev/playground/r/8KT5ron/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + version_id: 8KT5ron + shortlink: https://sg.run/wXvA + source: https://semgrep.dev/r/python.aws-lambda.security.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - aws-lambda + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\" % ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - pattern: "f\"$SQLSTR{...}...\"\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.*= + - pattern-not-inside: "print(...)\n" + pattern-sources: + - patterns: + - pattern: event + - pattern-inside: "def $HANDLER(event, context):\n ...\n" + severity: ERROR +- id: python.boto3.security.hardcoded-token.hardcoded-token + languages: + - python + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + - https://bento.dev/checks/boto3/hardcoded-access-token/ + - https://aws.amazon.com/blogs/security/what-to-do-if-you-inadvertently-expose-an-aws-access-key/ + semgrep.dev: + rule: + origin: community + r_id: 9439 + rule_id: 5rUOwK + rv_id: 1263347 + url: https://semgrep.dev/playground/r/gETB78n/python.boto3.security.hardcoded-token.hardcoded-token + version_id: gETB78n + shortlink: https://sg.run/LwQ6 + source: https://semgrep.dev/r/python.boto3.security.hardcoded-token.hardcoded-token + subcategory: + - vuln + technology: + - boto3 + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: $W(...,$TOKEN="$VALUE",...) + - pattern: $BOTO. ... .$W(...,$TOKEN="$VALUE",...) + - metavariable-regex: + metavariable: $TOKEN + regex: (aws_session_token|aws_access_key_id|aws_secret_access_key) + - metavariable-pattern: + language: generic + metavariable: $VALUE + patterns: + - pattern-either: + - pattern-regex: ^AKI + - pattern-regex: ^[A-Za-z0-9/+=]+$ + - metavariable-analysis: + analyzer: entropy + metavariable: $VALUE + pattern-sources: + - pattern: "\"...\"\n" + severity: WARNING +- id: python.cryptography.security.empty-aes-key.empty-aes-key + languages: + - python + message: Potential empty AES encryption key. Using an empty key in AES encryption can result in weak encryption and + may allow attackers to easily decrypt sensitive data. Ensure that a strong, non-empty key is used for AES + encryption. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + - 'CWE-310: Cryptographic Issues' + functional-categories: + - crypto::search::key-length::pycrypto + - crypto::search::key-length::pycryptodome + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: A6:2017 misconfiguration + references: + - https://cwe.mitre.org/data/definitions/327.html + - https://cwe.mitre.org/data/definitions/310.html + semgrep.dev: + rule: + origin: community + r_id: 44817 + rule_id: OrUADK + rv_id: 946105 + url: https://semgrep.dev/playground/r/8KTKjRg/python.cryptography.security.empty-aes-key.empty-aes-key + version_id: 8KTKjRg + shortlink: https://sg.run/zQ9G + source: https://semgrep.dev/r/python.cryptography.security.empty-aes-key.empty-aes-key + subcategory: + - vuln + technology: + - python + - pycrypto + - pycryptodome + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: AES.new("",...) + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + languages: + - python + message: ARC4 (Alleged RC4) is a stream cipher with serious weaknesses in its initial stream output. Its use is + strongly discouraged. ARC4 does not use mode constructions. Use a strong symmetric cipher such as EAS instead. With + the `cryptography` package it is recommended to use the `Fernet` which is a secure implementation of AES in CBC mode + with a 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES + algorithm instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + semgrep.dev: + rule: + origin: community + r_id: 33630 + rule_id: KxU8gK + rv_id: 1263348 + url: + https://semgrep.dev/playground/r/QkTGq3Q/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + version_id: QkTGq3Q + shortlink: https://sg.run/xoZL + source: + https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-arc4.insecure-cipher-algorithm-arc4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$ARC4($KEY) + - pattern-inside: cryptography.hazmat.primitives.ciphers.Cipher(...) + - metavariable-regex: + metavariable: $ARC4 + regex: ^(ARC4)$ + - focus-metavariable: $ARC4 + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + languages: + - python + message: Blowfish is a block cipher developed by Bruce Schneier. It is known to be susceptible to attacks when using + weak keys. The author has recommended that users of Blowfish move to newer algorithms such as AES. With the + `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a + 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm + instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#weak-ciphers + - https://tools.ietf.org/html/rfc5469 + semgrep.dev: + rule: + origin: community + r_id: 33631 + rule_id: qNULvO + rv_id: 1263349 + url: + https://semgrep.dev/playground/r/3ZT4XK7/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + version_id: 3ZT4XK7 + shortlink: https://sg.run/OdzL + source: + https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms-blowfish.insecure-cipher-algorithm-blowfish + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$BLOWFISH($KEY) + - metavariable-regex: + metavariable: $BLOWFISH + regex: ^(Blowfish)$ + - focus-metavariable: $BLOWFISH + severity: WARNING +- fix: AES + id: python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + languages: + - python + message: IDEA (International Data Encryption Algorithm) is a block cipher created in 1991. It is an optional + component of the OpenPGP standard. This cipher is susceptible to attacks when using weak keys. It is recommended + that you do not use this cipher for new applications. Use a strong symmetric cipher such as EAS instead. With the + `cryptography` package it is recommended to use `Fernet` which is a secure implementation of AES in CBC mode with a + 128-bit key. Alternatively, keep using the `Cipher` class from the hazmat primitives but use the AES algorithm + instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc5469 + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#cryptography.hazmat.primitives.ciphers.algorithms.IDEA + semgrep.dev: + rule: + origin: community + r_id: 9443 + rule_id: BYUNPg + rv_id: 1263350 + url: + https://semgrep.dev/playground/r/44TEjNJ/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + version_id: 44TEjNJ + shortlink: https://sg.run/3xyK + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-algorithms.insecure-cipher-algorithm-idea + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L98 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.ciphers.algorithms.$IDEA($KEY) + - metavariable-regex: + metavariable: $IDEA + regex: ^(IDEA)$ + - focus-metavariable: $IDEA + severity: WARNING +- fix: cryptography.hazmat.primitives.ciphers.modes.GCM($IV) + id: python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + languages: + - python + message: ECB (Electronic Code Book) is the simplest mode of operation for block ciphers. Each block of data is + encrypted in the same way. This means identical plaintext blocks will always result in identical ciphertext blocks, + which can leave significant patterns in the output. Use a different, cryptographically strong mode instead, such as + GCM. + metadata: + bandit-code: B305 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::mode::cryptography + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/symmetric-encryption/#insecure-modes + - https://crypto.stackexchange.com/questions/20941/why-shouldnt-i-use-ecb-encryption + semgrep.dev: + rule: + origin: community + r_id: 9444 + rule_id: DbUp5g + rv_id: 1263351 + url: + https://semgrep.dev/playground/r/PkTR3w7/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + version_id: PkTR3w7 + shortlink: https://sg.run/4xr5 + source: https://semgrep.dev/r/python.cryptography.security.insecure-cipher-mode-ecb.insecure-cipher-mode-ecb + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L101 + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + pattern: cryptography.hazmat.primitives.ciphers.modes.ECB($IV) + severity: WARNING +- fix: SHA256 + id: python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#md5 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33632 + rule_id: lBUopp + rv_id: 1263352 + url: + https://semgrep.dev/playground/r/JdTzxww/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + version_id: JdTzxww + shortlink: https://sg.run/eY88 + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$MD5() + - metavariable-regex: + metavariable: $MD5 + regex: ^(MD5)$ + - focus-metavariable: $MD5 + severity: WARNING +- fix: "SHA256\n" + id: python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/cryptographic-hashes/#sha-1 + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9446 + rule_id: 0oU5dN + rv_id: 1263353 + url: + https://semgrep.dev/playground/r/5PTo1l0/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + version_id: 5PTo1l0 + shortlink: https://sg.run/J9Qy + source: https://semgrep.dev/r/python.cryptography.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: cryptography.hazmat.primitives.hashes.$SHA(...) + - metavariable-pattern: + metavariable: $SHA + pattern: "SHA1\n" + - focus-metavariable: $SHA + severity: WARNING +- fix: "2048\n" + id: python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + languages: + - python + message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.cosic.esat.kuleuven.be/ecrypt/ecrypt2/documents/D.SPA.20.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/dsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + semgrep.dev: + rule: + origin: community + r_id: 9447 + rule_id: KxUb0x + rv_id: 1263354 + url: + https://semgrep.dev/playground/r/GxTkeOK/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + version_id: GxTkeOK + shortlink: https://sg.run/5Qb0 + source: https://semgrep.dev/r/python.cryptography.security.insufficient-dsa-key-size.insufficient-dsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key(..., key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.dsa.generate_private_key($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + - focus-metavariable: $SIZE + severity: WARNING +- fix: "SECP256R1\n" + id: python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + languages: + - python + message: Detected an insufficient curve size for EC. NIST recommends a key size of 224 or higher. For example, use + 'ec.SECP256R1'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves + semgrep.dev: + rule: + origin: community + r_id: 9448 + rule_id: qNUjZ3 + rv_id: 1263355 + url: + https://semgrep.dev/playground/r/RGT0LW6/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + version_id: RGT0LW6 + shortlink: https://sg.run/GeQq + source: https://semgrep.dev/r/python.cryptography.security.insufficient-ec-key-size.insufficient-ec-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: cryptography.hazmat.primitives.asymmetric.ec.generate_private_key(...) + - pattern: cryptography.hazmat.primitives.asymmetric.ec.$SIZE + - metavariable-pattern: + metavariable: $SIZE + pattern-either: + - pattern: SECP192R1 + - pattern: SECT163K1 + - pattern: SECT163R2 + - focus-metavariable: $SIZE + severity: WARNING +- fix: "2048\n" + id: python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + languages: + - python + message: Detected an insufficient key size for RSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::cryptography + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cryptography.io/en/latest/hazmat/primitives/asymmetric/rsa/ + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57Pt3r1.pdf + semgrep.dev: + rule: + origin: community + r_id: 9449 + rule_id: lBU9jn + rv_id: 1263356 + url: + https://semgrep.dev/playground/r/A8TgdPK/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + version_id: A8TgdPK + shortlink: https://sg.run/RoQq + source: https://semgrep.dev/r/python.cryptography.security.insufficient-rsa-key-size.insufficient-rsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key(..., key_size=$SIZE, ...) + - pattern: cryptography.hazmat.primitives.asymmetric.rsa.generate_private_key($EXP, $SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + - focus-metavariable: $SIZE + severity: WARNING +- id: python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + languages: + - python + message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result + in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 31871 + rule_id: lBUpNZ + rv_id: 1263357 + url: + https://semgrep.dev/playground/r/BjTkZj5/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + version_id: BjTkZj5 + shortlink: https://sg.run/N9JL + source: + https://semgrep.dev/r/python.cryptography.security.mode-without-authentication.crypto-mode-without-authentication + subcategory: + - audit + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - patterns: + - pattern: "Cipher(..., $HAZMAT_MODE(...),...)\n" + - pattern-not-inside: "Cipher(..., $HAZMAT_MODE(...),...)\n...\nHMAC(...)\n" + - pattern-not-inside: "Cipher(..., $HAZMAT_MODE(...),...)\n...\nhmac.HMAC(...)\n" + - metavariable-pattern: + metavariable: $HAZMAT_MODE + patterns: + - pattern-either: + - pattern: modes.CTR + - pattern: modes.CBC + - pattern: modes.CFB + - pattern: modes.OFB + severity: ERROR +- fix: "True\n" + id: python.distributed.security.require-encryption + languages: + - python + message: Initializing a security context for Dask (`distributed`) without "require_encryption" keyword argument may + silently fail to provide security. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://distributed.dask.org/en/latest/tls.html?highlight=require_encryption#parameters + semgrep.dev: + rule: + origin: community + r_id: 9450 + rule_id: YGURy0 + rv_id: 1263358 + url: https://semgrep.dev/playground/r/DkTRbol/python.distributed.security.require-encryption + version_id: DkTRbol + shortlink: https://sg.run/AvQ2 + source: https://semgrep.dev/r/python.distributed.security.require-encryption + subcategory: + - vuln + technology: + - distributed + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: "distributed.security.Security(..., require_encryption=$VAL, ...)\n" + - metavariable-pattern: + metavariable: $VAL + pattern: "False\n" + - focus-metavariable: $VAL + severity: WARNING +- id: python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + languages: + - python + message: Avoid using insecure deserialization library, backed by `pickle`, `_pickle`, `cpickle`, `dill`, `shelve`, or + `yaml`, which are known to lead to remote code execution vulnerabilities. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + semgrep.dev: + rule: + origin: community + r_id: 9467 + rule_id: OrU3e6 + rv_id: 1409400 + url: + https://semgrep.dev/playground/r/GxTlb9e/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + version_id: GxTlb9e + shortlink: https://sg.run/9oyr + source: + https://semgrep.dev/r/python.django.security.audit.avoid-insecure-deserialization.avoid-insecure-deserialization + subcategory: + - vuln + technology: + - django + vulnerability_class: + - 'Insecure Deserialization ' + mode: taint + pattern-sinks: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "pickle.$PICKLEFUNC(...)\n" + - pattern: "_pickle.$PICKLEFUNC(...)\n" + - pattern: "cPickle.$PICKLEFUNC(...)\n" + - pattern: "shelve.$PICKLEFUNC(...)\n" + - metavariable-regex: + metavariable: $PICKLEFUNC + regex: dumps|dump|load|loads + - patterns: + - pattern: dill.$DILLFUNC(...) + - metavariable-regex: + metavariable: $DILLFUNC + regex: dump|dump_session|dumps|load|load_session|loads + - patterns: + - pattern: yaml.$YAMLFUNC(...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Dumper=yaml.SafeDumper, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=SafeLoader, ...) + - pattern-not: yaml.$YAMLFUNC(..., Loader=yaml.SafeLoader, ...) + - metavariable-regex: + metavariable: $YAMLFUNC + regex: dump|dump_all|load|load_all + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: "def $INSIDE(..., $PARAM, ...):\n ...\n" + - pattern-either: + - pattern: request.$REQFUNC(...) + - pattern: request.$REQFUNC.get(...) + - pattern: request.$REQFUNC[...] + severity: ERROR +- id: python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + languages: + - python + message: Use $FORM.cleaned_data[] instead of request.POST[] after form.is_valid() has been executed to only access + sanitized data + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-20: Improper Input Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://docs.djangoproject.com/en/4.2/ref/forms/api/#accessing-clean-data + semgrep.dev: + rule: + origin: community + r_id: 73472 + rule_id: JDUjqx + rv_id: 946161 + url: + https://semgrep.dev/playground/r/DkTNpEJ/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + version_id: DkTNpEJ + shortlink: https://sg.run/kJn7 + source: + https://semgrep.dev/r/python.django.security.django-using-request-post-after-is-valid.django-using-request-post-after-is-valid + subcategory: + - audit + technology: + - django + vulnerability_class: + - Improper Validation + patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-inside: "if $FORM.is_valid():\n ...\n" + - pattern-either: + - pattern: request.POST[...] + - pattern: request.POST.get(...) + severity: WARNING +- id: python.django.security.hashids-with-django-secret.hashids-with-django-secret + languages: + - python + message: The Django secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient + HashIDs, the salt used to construct them can be recovered. This means the Django secret key can be obtained by + attackers, through the HashIDs. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 – Cryptographic Failures + references: + - https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + semgrep.dev: + rule: + origin: community + r_id: 72426 + rule_id: 0oUXqy + rv_id: 946163 + url: + https://semgrep.dev/playground/r/0bT15nn/python.django.security.hashids-with-django-secret.hashids-with-django-secret + version_id: 0bT15nn + shortlink: https://sg.run/bxeZ + source: https://semgrep.dev/r/python.django.security.hashids-with-django-secret.hashids-with-django-secret + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashids.Hashids(..., salt=django.conf.settings.SECRET_KEY, ...) + - pattern: hashids.Hashids(django.conf.settings.SECRET_KEY, ...) + severity: ERROR +- id: python.django.security.injection.code.user-eval-format-string.user-eval-format-string + languages: + - python + message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute + remote code. See https://owasp.org/www-community/attacks/Code_Injection for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9500 + rule_id: BYUNw9 + rv_id: 1263383 + url: + https://semgrep.dev/playground/r/vdT06xG/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + version_id: vdT06xG + shortlink: https://sg.run/4x2z + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval-format-string.user-eval-format-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: eval(..., $STR % request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., "..." % request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR % request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR % $V\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: eval(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR.format(..., $V, ...)\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W(...)\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + - pattern: "$V = request.$W[...]\n...\neval(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = f\"...{$V}...\"\n...\neval(..., $S, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-eval.user-eval + languages: + - python + message: Found user data in a call to 'eval'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9501 + rule_id: DbUpDQ + rv_id: 1263384 + url: https://semgrep.dev/playground/r/d6Tyx2A/python.django.security.injection.code.user-eval.user-eval + version_id: d6Tyx2A + shortlink: https://sg.run/PJDW + source: https://semgrep.dev/r/python.django.security.injection.code.user-eval.user-eval + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: eval(..., request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\neval(..., $V, ...)\n" + - pattern: eval(..., request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\neval(..., $V, ...)\n" + - pattern: eval(..., request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\neval(..., $V, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-exec-format-string.user-exec-format-string + languages: + - python + message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9502 + rule_id: WAUovx + rv_id: 1263385 + url: + https://semgrep.dev/playground/r/ZRTKA1p/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + version_id: ZRTKA1p + shortlink: https://sg.run/J9JW + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec-format-string.user-exec-format-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: exec(..., $STR % request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., "..." % request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR % request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $STR % $V, ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR % $V\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W.get(...), ...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W(...), ...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., $STR.format(..., request.$W[...], ...), ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $STR.format(..., $V, ...), ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = $STR.format(..., $V, ...)\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W.get(...)\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W.get(...)\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W(...)\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W(...)\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: "$V = request.$W[...]\n...\nexec(..., f\"...{$V}...\", ...)\n" + - pattern: "$V = request.$W[...]\n...\n$S = f\"...{$V}...\"\n...\nexec(..., $S, ...)\n" + - pattern: exec(..., base64.decodestring($S.format(..., request.$W.get(...), ...), ...), ...) + - pattern: exec(..., base64.decodestring($S % request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(f"...{request.$W.get(...)}...", ...), ...) + - pattern: exec(..., base64.decodestring(request.$W.get(...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S.format(..., request.$W.get(...), ...), ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes($S % request.$W.get(...), ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes(f"...{request.$W.get(...)}...", ...), ...), ...) + - pattern: exec(..., base64.decodestring(bytes(request.$W.get(...), ...), ...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\nexec(..., base64.decodestring($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = base64.decodestring($DATA, ...)\n...\nexec(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nexec(..., base64.decodestring(bytes($DATA, ...), ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = base64.decodestring(bytes($DATA, ...), ...)\n...\nexec(..., $INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.code.user-exec.user-exec + languages: + - python + message: Found user data in a call to 'exec'. This is extremely dangerous because it can enable an attacker to execute + arbitrary remote code on the system. Instead, refactor your code to not use 'eval' and instead use a safe library + for the specific functionality you need. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Code_Injection + semgrep.dev: + rule: + origin: community + r_id: 9503 + rule_id: 0oU5AW + rv_id: 1263386 + url: https://semgrep.dev/playground/r/nWT2LA2/python.django.security.injection.code.user-exec.user-exec + version_id: nWT2LA2 + shortlink: https://sg.run/5Q3X + source: https://semgrep.dev/r/python.django.security.injection.code.user-exec.user-exec + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Code Injection + patterns: + - pattern-inside: "def $F(...):\n ...\n" + - pattern-either: + - pattern: exec(..., request.$W.get(...), ...) + - pattern: "$V = request.$W.get(...)\n...\nexec(..., $V, ...)\n" + - pattern: exec(..., request.$W(...), ...) + - pattern: "$V = request.$W(...)\n...\nexec(..., $V, ...)\n" + - pattern: exec(..., request.$W[...], ...) + - pattern: "$V = request.$W[...]\n...\nexec(..., $V, ...)\n" + - pattern: "loop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, request.$W[...])\n" + - pattern: "$V = request.$W[...]\n...\nloop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, + $V)\n" + - pattern: "loop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, request.$W.get(...))\n" + - pattern: "$V = request.$W.get(...)\n...\nloop = asyncio.get_running_loop()\n...\nawait loop.run_in_executor(None, exec, + $V)\n" + severity: WARNING +- id: python.django.security.injection.command.command-injection-os-system.command-injection-os-system + languages: + - python + message: Request data detected in os.system. This could be vulnerable to a command injection and should be avoided. If + this must be done, use the 'subprocess' module instead and pass the arguments as a list. See + https://owasp.org/www-community/attacks/Command_Injection for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + semgrep.dev: + rule: + origin: community + r_id: 9504 + rule_id: KxUbp2 + rv_id: 1263387 + url: + https://semgrep.dev/playground/r/ExTExPo/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + version_id: ExTExPo + shortlink: https://sg.run/Gen2 + source: + https://semgrep.dev/r/python.django.security.injection.command.command-injection-os-system.command-injection-os-system + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Command Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: os.system(..., request.$W.get(...), ...) + - pattern: os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: os.system(..., $S % request.$W.get(...), ...) + - pattern: os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W.get(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W.get(...), ...) + - pattern: $A = os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: return os.system(..., request.$W.get(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return os.system(..., $S % request.$W.get(...), ...) + - pattern: return os.system(..., f"...{request.$W.get(...)}...", ...) + - pattern: os.system(..., request.$W(...), ...) + - pattern: os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: os.system(..., $S % request.$W(...), ...) + - pattern: os.system(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W(...), ...) + - pattern: $A = os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = os.system(..., $S % request.$W(...), ...) + - pattern: $A = os.system(..., f"...{request.$W(...)}...", ...) + - pattern: return os.system(..., request.$W(...), ...) + - pattern: return os.system(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return os.system(..., $S % request.$W(...), ...) + - pattern: return os.system(..., f"...{request.$W(...)}...", ...) + - pattern: os.system(..., request.$W[...], ...) + - pattern: os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: os.system(..., $S % request.$W[...], ...) + - pattern: os.system(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W[...], ...) + - pattern: $A = os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = os.system(..., $S % request.$W[...], ...) + - pattern: $A = os.system(..., f"...{request.$W[...]}...", ...) + - pattern: return os.system(..., request.$W[...], ...) + - pattern: return os.system(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return os.system(..., $S % request.$W[...], ...) + - pattern: return os.system(..., f"...{request.$W[...]}...", ...) + - pattern: os.system(..., request.$W, ...) + - pattern: os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: os.system(..., $S % request.$W, ...) + - pattern: os.system(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nos.system(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nos.system(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nos.system(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nos.system(..., $INTERM, ...)\n" + - pattern: $A = os.system(..., request.$W, ...) + - pattern: $A = os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = os.system(..., $S % request.$W, ...) + - pattern: $A = os.system(..., f"...{request.$W}...", ...) + - pattern: return os.system(..., request.$W, ...) + - pattern: return os.system(..., $S.format(..., request.$W, ...), ...) + - pattern: return os.system(..., $S % request.$W, ...) + - pattern: return os.system(..., f"...{request.$W}...", ...) + severity: ERROR +- id: python.django.security.injection.command.subprocess-injection.subprocess-injection + languages: + - python + message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection + vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them + to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the + command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a + dictionary to allowlist a set of commands. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 31144 + rule_id: EwUepx + rv_id: 1263388 + url: + https://semgrep.dev/playground/r/7ZTE3qK/python.django.security.injection.command.subprocess-injection.subprocess-injection + version_id: 7ZTE3qK + shortlink: https://sg.run/49BE + source: https://semgrep.dev/r/python.django.security.injection.command.subprocess-injection.subprocess-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: "$CMD = [\"...\", ...]\n...\nsubprocess.$FUNC($CMD, ...)\n" + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sources: + - patterns: + - pattern-inside: "def $FUNC(..., $REQUEST, ...):\n ...\n" + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + severity: ERROR +- id: python.django.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to + generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into + a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, + install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to + mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + semgrep.dev: + rule: + origin: community + r_id: 31145 + rule_id: 7KUK1y + rv_id: 1263389 + url: + https://semgrep.dev/playground/r/LjTkgD9/python.django.security.injection.csv-writer-injection.csv-writer-injection + version_id: LjTkgD9 + shortlink: https://sg.run/Pw9q + source: https://semgrep.dev/r/python.django.security.injection.csv-writer-injection.csv-writer-injection + subcategory: + - vuln + technology: + - django + - python + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$WRITER = csv.writer(...)\n\n...\n\n$WRITER.$WRITE(...)\n" + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-inside: "def $FUNC(..., $REQUEST, ...):\n ...\n" + - focus-metavariable: $REQUEST + - metavariable-pattern: + metavariable: $REQUEST + patterns: + - pattern: request + - pattern-not-inside: request.build_absolute_uri + severity: ERROR +- id: python.django.security.injection.email.xss-html-email-body.xss-html-email-body + languages: + - python + message: Found request data in an EmailMessage that is set to use HTML. This is dangerous because HTML emails are + susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + semgrep.dev: + rule: + origin: community + r_id: 9505 + rule_id: qNUj02 + rv_id: 1263390 + url: + https://semgrep.dev/playground/r/8KT5rOn/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + version_id: 8KT5rOn + shortlink: https://sg.run/RoBe + source: https://semgrep.dev/r/python.django.security.injection.email.xss-html-email-body.xss-html-email-body + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Other + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n $EMAIL.content_subtype = \"html\"\n ...\n" + - pattern-either: + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W.get(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W(...), ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W[...], ...) + - pattern: django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.EmailMessage($SUBJ, f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.EmailMessage($SUBJ, $INTERM, + ...)\n" + - pattern: $A = django.core.mail.EmailMessage($SUBJ, request.$W, ...) + - pattern: return django.core.mail.EmailMessage($SUBJ, request.$W, ...) + severity: WARNING +- id: python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + languages: + - python + message: Found request data in 'send_mail(...)' that uses 'html_message'. This is dangerous because HTML emails are + susceptible to XSS. An attacker could inject data into this HTML email, causing XSS. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://www.damonkohler.com/2008/12/email-injection.html + semgrep.dev: + rule: + origin: community + r_id: 9506 + rule_id: lBU9Ll + rv_id: 1263391 + url: + https://semgrep.dev/playground/r/gETB7Gn/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + version_id: gETB7Gn + shortlink: https://sg.run/Avx8 + source: + https://semgrep.dev/r/python.django.security.injection.email.xss-send-mail-html-message.xss-send-mail-html-message + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Other + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W.get(...), ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W(...), ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., + html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W[...], ...) + - pattern: django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.core.mail.send_mail(..., html_message=$STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.core.mail.send_mail(..., html_message=$INTERM, + ...)\n" + - pattern: $A = django.core.mail.send_mail(..., html_message=request.$W, ...) + - pattern: return django.core.mail.send_mail(..., html_message=request.$W, ...) + severity: WARNING +- id: python.django.security.injection.open-redirect.open-redirect + languages: + - python + message: Data from request ($DATA) is passed to redirect(). This is an open redirect and could be exploited. Ensure + you are redirecting to safe URLs by using django.utils.http.is_safe_url(). See + https://cwe.mitre.org/data/definitions/601.html for more information. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.djm.org.uk/posts/djangos-little-protections-word-redirect-dangers/ + - https://github.com/django/django/blob/d1b7bd030b1db111e1a3505b1fc029ab964382cc/django/utils/http.py#L231 + semgrep.dev: + rule: + origin: community + r_id: 9494 + rule_id: PeUZgr + rv_id: 1263393 + url: https://semgrep.dev/playground/r/3ZT4XD7/python.django.security.injection.open-redirect.open-redirect + version_id: 3ZT4XD7 + shortlink: https://sg.run/Ave2 + source: https://semgrep.dev/r/python.django.security.injection.open-redirect.open-redirect + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Open Redirect + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n django.utils.http.is_safe_url(...)\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n if <... django.utils.http.is_safe_url(...) ...>:\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n django.utils.http.url_has_allowed_host_and_scheme(...)\n ...\n" + - pattern-not-inside: "def $FUNC(...):\n ...\n if <... django.utils.http.url_has_allowed_host_and_scheme(...) ...>:\n\ + \ ...\n" + - pattern-either: + - pattern: django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W.get(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W(...), ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W(...)}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W[...], ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W[...]}...", ...) + - pattern: django.shortcuts.redirect(..., request.$W, ...) + - pattern: django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.shortcuts.redirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.shortcuts.redirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.shortcuts.redirect(..., $INTERM, ...)\n" + - pattern: $A = django.shortcuts.redirect(..., request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: $A = django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: return django.shortcuts.redirect(..., request.$W, ...) + - pattern: return django.shortcuts.redirect(..., $S.format(..., request.$W, ...), ...) + - pattern: return django.shortcuts.redirect(..., $S % request.$W, ...) + - pattern: return django.shortcuts.redirect(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W.get(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W(...), ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W[...], ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseRedirect(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseRedirect(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseRedirect(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: $A = django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - pattern: return django.http.HttpResponseRedirect(..., request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., $S.format(..., request.$W, ...), ...) + - pattern: return django.http.HttpResponseRedirect(..., $S % request.$W, ...) + - pattern: return django.http.HttpResponseRedirect(..., f"...{request.$W}...", ...) + - metavariable-regex: + metavariable: $W + regex: (?!get_full_path) + severity: WARNING +- id: python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + languages: + - python + message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could + result in path traversal attacks and therefore sensitive data being leaked. To mitigate, consider using + os.path.abspath or os.path.realpath or the pathlib library. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9509 + rule_id: oqUe7z + rv_id: 1263396 + url: + https://semgrep.dev/playground/r/JdTzxAw/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + version_id: JdTzxAw + shortlink: https://sg.run/W8qg + source: + https://semgrep.dev/r/python.django.security.injection.path-traversal.path-traversal-open.path-traversal-open + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Path Traversal + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: open(..., request.$W.get(...), ...) + - pattern: open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: open(..., $S % request.$W.get(...), ...) + - pattern: open(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) + as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n\ + \ ...\n" + - pattern: "$DATA = request.$W.get(...)\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W.get(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $A = open(..., $S % request.$W.get(...), ...) + - pattern: $A = open(..., f"...{request.$W.get(...)}...", ...) + - pattern: return open(..., request.$W.get(...), ...) + - pattern: return open(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: return open(..., $S % request.$W.get(...), ...) + - pattern: return open(..., f"...{request.$W.get(...)}...", ...) + - pattern: "$DATA = request.$W.get(...)\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W(...), ...) + - pattern: open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: open(..., $S % request.$W(...), ...) + - pattern: open(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as + $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W(...)\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W(...), ...) + - pattern: $A = open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $A = open(..., $S % request.$W(...), ...) + - pattern: $A = open(..., f"...{request.$W(...)}...", ...) + - pattern: return open(..., request.$W(...), ...) + - pattern: return open(..., $S.format(..., request.$W(...), ...), ...) + - pattern: return open(..., $S % request.$W(...), ...) + - pattern: return open(..., f"...{request.$W(...)}...", ...) + - pattern: "$DATA = request.$W(...)\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W[...], ...) + - pattern: open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: open(..., $S % request.$W[...], ...) + - pattern: open(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as + $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W[...]\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W[...], ...) + - pattern: $A = open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $A = open(..., $S % request.$W[...], ...) + - pattern: $A = open(..., f"...{request.$W[...]}...", ...) + - pattern: return open(..., request.$W[...], ...) + - pattern: return open(..., $S.format(..., request.$W[...], ...), ...) + - pattern: return open(..., $S % request.$W[...], ...) + - pattern: return open(..., f"...{request.$W[...]}...", ...) + - pattern: "$DATA = request.$W[...]\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + - pattern: open(..., request.$W, ...) + - pattern: open(..., $S.format(..., request.$W, ...), ...) + - pattern: open(..., $S % request.$W, ...) + - pattern: open(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nwith open(..., $INTERM, ...) as $FD:\n\ + \ ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: "$DATA = request.$W\n...\nopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nwith open(..., $INTERM, ...) as $FD:\n ...\n" + - pattern: $A = open(..., request.$W, ...) + - pattern: $A = open(..., $S.format(..., request.$W, ...), ...) + - pattern: $A = open(..., $S % request.$W, ...) + - pattern: $A = open(..., f"...{request.$W}...", ...) + - pattern: return open(..., request.$W, ...) + - pattern: return open(..., $S.format(..., request.$W, ...), ...) + - pattern: return open(..., $S % request.$W, ...) + - pattern: return open(..., f"...{request.$W}...", ...) + - pattern: "$DATA = request.$W\n...\nwith open(..., $DATA, ...) as $FD:\n ...\n" + severity: WARNING +- id: python.django.security.injection.raw-html-format.raw-html-format + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates (`django.shortcuts.render`) which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.2/topics/http/shortcuts/#render + - https://docs.djangoproject.com/en/3.2/topics/security/#cross-site-scripting-xss-protection + semgrep.dev: + rule: + origin: community + r_id: 14360 + rule_id: 2ZUPER + rv_id: 1263397 + url: https://semgrep.dev/playground/r/5PTo100/python.django.security.injection.raw-html-format.raw-html-format + version_id: 5PTo100 + shortlink: https://sg.run/oYj1 + source: https://semgrep.dev/r/python.django.security.injection.raw-html-format.raw-html-format + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: django.utils.html.escape(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern: request.$ANYTHING + - pattern-not: request.build_absolute_uri + severity: WARNING +- id: python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + languages: + - python + message: Found user-controlled request data passed into HttpResponse. This could be vulnerable to XSS, leading to + attackers gaining access to user cookies and protected information. Ensure that the request data is properly escaped + or sanitzed. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9495 + rule_id: JDUydR + rv_id: 1263398 + url: + https://semgrep.dev/playground/r/GxTke5K/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + version_id: GxTke5K + shortlink: https://sg.run/BkvA + source: + https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponse.reflected-data-httpresponse + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponse(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W(...), ...) + - pattern: return django.http.HttpResponse(..., request.$W(...), ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponse(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W[...], ...) + - pattern: return django.http.HttpResponse(..., request.$W[...], ...) + - pattern: django.http.HttpResponse(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponse(..., $S % request.$W, ...) + - pattern: django.http.HttpResponse(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponse(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., f\"...{$DATA}...\", ...)\n" + - pattern: $A = django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$A = django.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: return django.http.HttpResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponse(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponse(..., $INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + languages: + - python + message: Found user-controlled request data passed into a HttpResponseBadRequest. This could be vulnerable to XSS, + leading to attackers gaining access to user cookies and protected information. Ensure that the request data is + properly escaped or sanitzed. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9496 + rule_id: 5rUOX1 + rv_id: 1263399 + url: + https://semgrep.dev/playground/r/RGT0LY6/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + version_id: RGT0LY6 + shortlink: https://sg.run/DoZP + source: + https://semgrep.dev/r/python.django.security.injection.reflected-data-httpresponsebadrequest.reflected-data-httpresponsebadrequest + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W.get(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W(...)}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W(...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W[...]}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W[...], ...) + - pattern: django.http.HttpResponseBadRequest(..., $S.format(..., request.$W, ...), ...) + - pattern: django.http.HttpResponseBadRequest(..., $S % request.$W, ...) + - pattern: django.http.HttpResponseBadRequest(..., f"...{request.$W}...", ...) + - pattern: django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.http.HttpResponseBadRequest(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.http.HttpResponseBadRequest(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.http.HttpResponseBadRequest(..., $INTERM, ...)\n" + - pattern: $A = django.http.HttpResponseBadRequest(..., request.$W, ...) + - pattern: return django.http.HttpResponseBadRequest(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.request-data-fileresponse.request-data-fileresponse + languages: + - python + message: Found user-controlled request data being passed into a file open, which is them passed as an argument into + the FileResponse. This is dangerous because an attacker could specify an arbitrary file to read, which could result + in leaking important data. Be sure to validate or sanitize the user-inputted filename in the request data before + using it in FileResponse. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://django-book.readthedocs.io/en/latest/chapter20.html#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9497 + rule_id: GdU7QR + rv_id: 1263400 + url: + https://semgrep.dev/playground/r/A8Tgd1K/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + version_id: A8Tgd1K + shortlink: https://sg.run/W862 + source: https://semgrep.dev/r/python.django.security.injection.request-data-fileresponse.request-data-fileresponse + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Path Traversal + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, + ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: return django.http.FileResponse(..., request.$W.get(...), ...) + - pattern: django.http.FileResponse(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W(...), ...) + - pattern: return django.http.FileResponse(..., request.$W(...), ...) + - pattern: django.http.FileResponse(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W[...], ...) + - pattern: return django.http.FileResponse(..., request.$W[...], ...) + - pattern: django.http.FileResponse(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.http.FileResponse(..., open($DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = open($DATA, ...)\n...\ndjango.http.FileResponse(..., $INTERM, ...)\n" + - pattern: $A = django.http.FileResponse(..., request.$W, ...) + - pattern: return django.http.FileResponse(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.request-data-write.request-data-write + languages: + - python + message: Found user-controlled request data passed into '.write(...)'. This could be dangerous if a malicious actor is + able to control data into sensitive files. For example, a malicious actor could force rolling of critical log files, + or cause a denial-of-service by using up available disk space. Instead, ensure that request data is properly escaped + or sanitized. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9498 + rule_id: ReUg5z + rv_id: 1263401 + url: + https://semgrep.dev/playground/r/BjTkZO5/python.django.security.injection.request-data-write.request-data-write + version_id: BjTkZO5 + shortlink: https://sg.run/0Q6j + source: https://semgrep.dev/r/python.django.security.injection.request-data-write.request-data-write + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Validation + pattern-either: + - pattern: $F.write(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W.get(...), ...) + - pattern: return $F.write(..., request.$W.get(...), ...) + - pattern: $F.write(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W(...), ...) + - pattern: return $F.write(..., request.$W(...), ...) + - pattern: $F.write(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W[...], ...) + - pattern: return $F.write(..., request.$W[...], ...) + - pattern: $F.write(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$F.write(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., $B.$C(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $B.$C(..., $DATA, ...)\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$F.write(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$F.write(..., $INTERM, ...)\n" + - pattern: $A = $F.write(..., request.$W, ...) + - pattern: return $F.write(..., request.$W, ...) + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + languages: + - python + message: User-controlled data from a request is passed to 'extra()'. This could lead to a SQL injection and therefore + protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by + using `params` and not using quote placeholders in the SQL string. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#.objects.extra + semgrep.dev: + rule: + origin: community + r_id: 9510 + rule_id: zdUkx1 + rv_id: 1263402 + url: + https://semgrep.dev/playground/r/DkTRb4l/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + version_id: DkTRb4l + shortlink: https://sg.run/0Ql5 + source: + https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-extra.sql-injection-using-extra-where + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W.get(...), ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W.get(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W.get(...)}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W.get(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W(...), ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W(...)}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W(...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W[...], ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W[...]}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W[...], ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S.format(..., request.$W, ...), ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., $S % request.$W, ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., f"...{request.$W}...", ...], ...) + - pattern: $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR.format(..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR % $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., f\"...{$DATA}...\", ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR + $DATA, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, ...], + ...)\n" + - pattern: $A = $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: return $MODEL.objects.extra(..., where=[..., request.$W, ...], ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.extra(..., where=[..., $STR % (..., $DATA, ...), ...], ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., + $INTERM, ...], ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.extra(..., where=[..., $INTERM, + ...], ...)\n" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + languages: + - python + message: User-controlled data from request is passed to 'RawSQL()'. This could lead to a SQL injection and therefore + protected information could be leaked. Instead, use parameterized queries or escape the user-controlled data by + using `params` and not using quote placeholders in the SQL string. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/ref/models/expressions/#django.db.models.expressions.RawSQL + semgrep.dev: + rule: + origin: community + r_id: 9511 + rule_id: pKUOBp + rv_id: 1263403 + url: + https://semgrep.dev/playground/r/WrTqK2L/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + version_id: WrTqK2L + shortlink: https://sg.run/Kl4X + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-rawsql.sql-injection-using-rawsql + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W.get(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W.get(...)}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W.get(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W(...), ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W(...)}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W(...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W[...], ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W[...]}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W[...], ...) + - pattern: django.db.models.expressions.RawSQL(..., $S.format(..., request.$W, ...), ...) + - pattern: django.db.models.expressions.RawSQL(..., $S % request.$W, ...) + - pattern: django.db.models.expressions.RawSQL(..., f"...{request.$W}...", ...) + - pattern: django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\ndjango.db.models.expressions.RawSQL(..., $INTERM, ...)\n" + - pattern: $A = django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: return django.db.models.expressions.RawSQL(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\ndjango.db.models.expressions.RawSQL($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\ndjango.db.models.expressions.RawSQL($INTERM, + ...)\n" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + languages: + - python + message: User-controlled data from a request is passed to 'execute()'. This could lead to a SQL injection and + therefore protected information could be leaked. Instead, use django's QuerySets, which are built with query + parameterization and therefore not vulnerable to sql injection. For example, you could use + `Entry.objects.filter(date=2006)`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + semgrep.dev: + rule: + origin: community + r_id: 9512 + rule_id: 2ZUbDL + rv_id: 1263404 + url: + https://semgrep.dev/playground/r/0bTKzRj/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + version_id: 0bTKzRj + shortlink: https://sg.run/qx7y + source: + https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-db-cursor-execute.sql-injection-db-cursor-execute + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $CURSOR.execute(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W.get(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: return $CURSOR.execute(..., request.$W.get(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W(...), ...) + - pattern: $CURSOR.execute(..., f"...{request.$W(...)}...", ...) + - pattern: $CURSOR.execute(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W(...), ...) + - pattern: return $CURSOR.execute(..., request.$W(...), ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W[...], ...) + - pattern: $CURSOR.execute(..., f"...{request.$W[...]}...", ...) + - pattern: $CURSOR.execute(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W[...], ...) + - pattern: return $CURSOR.execute(..., request.$W[...], ...) + - pattern: $CURSOR.execute(..., $S.format(..., request.$W, ...), ...) + - pattern: $CURSOR.execute(..., $S % request.$W, ...) + - pattern: $CURSOR.execute(..., f"...{request.$W}...", ...) + - pattern: $CURSOR.execute(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$CURSOR.execute(..., $INTERM, ...)\n" + - pattern: $A = $CURSOR.execute(..., request.$W, ...) + - pattern: return $CURSOR.execute(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$CURSOR.execute($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$CURSOR.execute($INTERM, ...)" + severity: WARNING +- id: python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + languages: + - python + message: Data that is possible user-controlled from a python request is passed to `raw()`. This could lead to SQL + injection and attackers gaining access to protected information. Instead, use django's QuerySets, which are built + with query parameterization and therefore not vulnerable to sql injection. For example, you could use + `Entry.objects.filter(date=2006)`. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.djangoproject.com/en/3.0/topics/security/#sql-injection-protection + semgrep.dev: + rule: + origin: community + r_id: 9513 + rule_id: X5U8v5 + rv_id: 1263405 + url: + https://semgrep.dev/playground/r/K3TKkBW/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + version_id: K3TKkBW + shortlink: https://sg.run/l2v9 + source: https://semgrep.dev/r/python.django.security.injection.sql.sql-injection-using-raw.sql-injection-using-raw + subcategory: + - vuln + technology: + - django + vulnerability_class: + - SQL Injection + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W.get(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W.get(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W(...), ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W(...)}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: return $MODEL.objects.raw(..., request.$W(...), ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W[...], ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W[...]}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: return $MODEL.objects.raw(..., request.$W[...], ...) + - pattern: $MODEL.objects.raw(..., $S.format(..., request.$W, ...), ...) + - pattern: $MODEL.objects.raw(..., $S % request.$W, ...) + - pattern: $MODEL.objects.raw(..., f"...{request.$W}...", ...) + - pattern: $MODEL.objects.raw(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\n$MODEL.objects.raw(..., $INTERM, ...)\n" + - pattern: $A = $MODEL.objects.raw(..., request.$W, ...) + - pattern: return $MODEL.objects.raw(..., request.$W, ...) + - pattern: "$DATA = request.$W.get(...)\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$MODEL.objects.raw($STR % (..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % (..., $DATA, ...)\n...\n$MODEL.objects.raw($INTERM, ...)\n" + severity: WARNING +- id: python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the + response to the user, and ensure proper authentication and transport-layer security in the proxied request. See + https://owasp.org/www-community/attacks/Server_Side_Request_Forgery to learn more about SSRF vulnerabilities. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9514 + rule_id: j2UvEw + rv_id: 1263406 + url: + https://semgrep.dev/playground/r/qkTR7zn/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + version_id: qkTR7zn + shortlink: https://sg.run/YvY4 + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-requests.ssrf-injection-requests + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Server-Side Request Forgery (SSRF) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: requests.$METHOD(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W.get(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W.get(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W.get(...), ...) + - pattern: return requests.$METHOD(..., request.$W.get(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W(...), ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W(...), ...) + - pattern: requests.$METHOD(..., f"...{request.$W(...)}...", ...) + - pattern: requests.$METHOD(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W(...), ...) + - pattern: return requests.$METHOD(..., request.$W(...), ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W[...], ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W[...], ...) + - pattern: requests.$METHOD(..., f"...{request.$W[...]}...", ...) + - pattern: requests.$METHOD(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W[...], ...) + - pattern: return requests.$METHOD(..., request.$W[...], ...) + - pattern: requests.$METHOD(..., $S.format(..., request.$W, ...), ...) + - pattern: requests.$METHOD(..., $S % request.$W, ...) + - pattern: requests.$METHOD(..., f"...{request.$W}...", ...) + - pattern: requests.$METHOD(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nrequests.$METHOD(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nrequests.$METHOD(..., $INTERM, ...)\n" + - pattern: $A = requests.$METHOD(..., request.$W, ...) + - pattern: return requests.$METHOD(..., request.$W, ...) + severity: ERROR +- id: python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF), which could result in attackers gaining access to private organization data. To mitigate, ensure + that schemes and hosts are validated against an allowlist, do not forward the response to the user, and ensure + proper authentication and transport-layer security in the proxied request. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9515 + rule_id: 10UKDo + rv_id: 1263407 + url: + https://semgrep.dev/playground/r/l4TJRwD/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + version_id: l4TJRwD + shortlink: https://sg.run/6n2B + source: https://semgrep.dev/r/python.django.security.injection.ssrf.ssrf-injection-urllib.ssrf-injection-urllib + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Server-Side Request Forgery (SSRF) + patterns: + - pattern-inside: "def $FUNC(...):\n ...\n" + - pattern-either: + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W.get(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W.get(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., + $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W.get(...)\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W.get(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W(...), ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W(...), ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W(...)}...", ...) + - pattern: urllib.request.urlopen(..., request.$W(...), ...) + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W(...)\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W(...), ...) + - pattern: return urllib.request.urlopen(..., request.$W(...), ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W[...], ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W[...], ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W[...]}...", ...) + - pattern: urllib.request.urlopen(..., request.$W[...], ...) + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W[...]\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W[...], ...) + - pattern: return urllib.request.urlopen(..., request.$W[...], ...) + - pattern: urllib.request.urlopen(..., $S.format(..., request.$W, ...), ...) + - pattern: urllib.request.urlopen(..., $S % request.$W, ...) + - pattern: urllib.request.urlopen(..., f"...{request.$W}...", ...) + - pattern: urllib.request.urlopen(..., request.$W, ...) + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR.format(..., $DATA, ...), ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR.format(..., $DATA, ...)\n...\nurllib.request.urlopen(..., $INTERM, + ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR % $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR % $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., f\"...{$DATA}...\", ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = f\"...{$DATA}...\"\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: "$DATA = request.$W\n...\nurllib.request.urlopen(..., $STR + $DATA, ...)\n" + - pattern: "$DATA = request.$W\n...\n$INTERM = $STR + $DATA\n...\nurllib.request.urlopen(..., $INTERM, ...)\n" + - pattern: $A = urllib.request.urlopen(..., request.$W, ...) + - pattern: return urllib.request.urlopen(..., request.$W, ...) + severity: ERROR +- id: python.django.security.nan-injection.nan-injection + languages: + - python + message: Found user input going directly into typecast for bool(), float(), or complex(). This allows an attacker to + inject Python's not-a-number (NaN) into the typecast. This results in undefind behavior, particularly when doing + comparisons. Either cast to a different type, or add a guard checking for all capitalizations of the string 'nan'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 + - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ + semgrep.dev: + rule: + origin: community + r_id: 18275 + rule_id: DbUGvk + rv_id: 946193 + url: https://semgrep.dev/playground/r/NdTqk7G/python.django.security.nan-injection.nan-injection + version_id: NdTqk7G + shortlink: https://sg.run/Og7L + source: https://semgrep.dev/r/python.django.security.nan-injection.nan-injection + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - not_conflicting: true + pattern: $ANYTHING(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: float(...) + - pattern: bool(...) + - pattern: complex(...) + - pattern-not-inside: "if $COND:\n ...\n...\n" + pattern-sources: + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + severity: ERROR +- id: python.django.security.passwords.password-empty-string.password-empty-string + languages: + - python + message: "'$VAR' is the empty string and is being used to set the password on '$MODEL'. If you meant to set an unusable + password, set the password to None or call 'set_unusable_password()'." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-521: Weak Password Requirements' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + semgrep.dev: + rule: + origin: community + r_id: 9516 + rule_id: 9AU1jW + rv_id: 1263411 + url: + https://semgrep.dev/playground/r/GxTke5Q/python.django.security.passwords.password-empty-string.password-empty-string + version_id: GxTke5Q + shortlink: https://sg.run/oxnR + source: https://semgrep.dev/r/python.django.security.passwords.password-empty-string.password-empty-string + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: "$MODEL.set_password($EMPTY)\n...\n$MODEL.save()\n" + - pattern: "$VAR = $EMPTY\n...\n$MODEL.set_password($VAR)\n...\n$MODEL.save()\n" + - metavariable-regex: + metavariable: $EMPTY + regex: (\'\'|\"\") + severity: ERROR +- fix: "None\n" + id: python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + languages: + - python + message: "'$VAR' is using the empty string as its default and is being used to set the password on '$MODEL'. If you meant + to set an unusable password, set the default value to 'None' or call 'set_unusable_password()'." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-521: Weak Password Requirements' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.djangoproject.com/en/3.0/ref/contrib/auth/#django.contrib.auth.models.User.set_password + semgrep.dev: + rule: + origin: community + r_id: 9517 + rule_id: yyUn6Z + rv_id: 1263412 + url: + https://semgrep.dev/playground/r/RGT0LYX/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + version_id: RGT0LYX + shortlink: https://sg.run/zvBW + source: + https://semgrep.dev/r/python.django.security.passwords.use-none-for-password-default.use-none-for-password-default + subcategory: + - vuln + technology: + - django + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: "$VAR = request.$W.get($X, $EMPTY)\n...\n$MODEL.set_password($VAR)\n...\n$MODEL.save(...)\n" + - pattern: "def $F(..., $VAR=$EMPTY, ...):\n ...\n $MODEL.set_password($VAR)\n" + - metavariable-pattern: + metavariable: $EMPTY + pattern: '""' + - focus-metavariable: $EMPTY + severity: ERROR +- id: python.fastapi.security.wildcard-cors.wildcard-cors + languages: + - python + message: CORS policy allows any origin (using wildcard '*'). This is insecure and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-942: Permissive Cross-domain Policy with Untrusted Domains' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + - https://cwe.mitre.org/data/definitions/942.html + semgrep.dev: + rule: + origin: community + r_id: 112311 + rule_id: lBU4JQ3 + rv_id: 1263413 + url: https://semgrep.dev/playground/r/A8Tgd1R/python.fastapi.security.wildcard-cors.wildcard-cors + version_id: A8Tgd1R + shortlink: https://sg.run/KxApY + source: https://semgrep.dev/r/python.fastapi.security.wildcard-cors.wildcard-cors + subcategory: + - vuln + technology: + - python + - fastapi + vulnerability_class: + - Configuration + mode: taint + pattern-sinks: + - patterns: + - pattern: "$APP.add_middleware(\n CORSMiddleware,\n allow_origins=$ORIGIN,\n ...);\n" + - focus-metavariable: $ORIGIN + pattern-sources: + - pattern: '[..., "*", ...]' + severity: WARNING +- id: python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + languages: + - python + message: Running flask app with host 0.0.0.0 could expose the server publicly. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9532 + rule_id: L1Uy1n + rv_id: 1263414 + url: + https://semgrep.dev/playground/r/BjTkZOY/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + version_id: BjTkZOY + shortlink: https://sg.run/eLby + source: https://semgrep.dev/r/python.flask.security.audit.app-run-param-config.avoid_app_run_with_bad_host + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Other + pattern-either: + - pattern: app.run(..., host="0.0.0.0", ...) + - pattern: app.run(..., "0.0.0.0", ...) + severity: WARNING +- id: python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + languages: + - python + message: top-level app.run(...) is ignored by flask. Consider putting app.run(...) behind a guard, like inside a + function + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-668: Exposure of Resource to Wrong Sphere' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9533 + rule_id: 8GUjdX + rv_id: 1263415 + url: + https://semgrep.dev/playground/r/DkTRb4z/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + version_id: DkTRb4z + shortlink: https://sg.run/vz5b + source: https://semgrep.dev/r/python.flask.security.audit.app-run-security-config.avoid_using_app_run_directly + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Other + patterns: + - pattern-not-inside: "if __name__ == '__main__':\n ...\n" + - pattern-not-inside: "def $X(...):\n ...\n" + - pattern: app.run(...) + severity: WARNING +- id: python.flask.security.audit.debug-enabled.debug-enabled + languages: + - python + message: Detected Flask app with debug=True. Do not deploy to production with this flag enabled as it will leak + sensitive information. Instead, consider using Flask configuration variables or setting 'debug' using system + environment variables. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-489: Active Debug Code' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: A06:2017 - Security Misconfiguration + references: + - https://labs.detectify.com/2015/10/02/how-patreon-got-hacked-publicly-exposed-werkzeug-debugger/ + semgrep.dev: + rule: + origin: community + r_id: 9534 + rule_id: gxU1bd + rv_id: 946206 + url: https://semgrep.dev/playground/r/8KTKjwR/python.flask.security.audit.debug-enabled.debug-enabled + version_id: 8KTKjwR + shortlink: https://sg.run/dKrd + source: https://semgrep.dev/r/python.flask.security.audit.debug-enabled.debug-enabled + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Active Debug Code + patterns: + - pattern-inside: "import flask\n...\n" + - pattern: $APP.run(..., debug=True, ...) + severity: WARNING +- id: python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + languages: + - python + message: Detected Flask route directly returning a formatted string. This is subject to cross-site scripting if user + input can reach the string. Consider using the template engine instead and rendering pages with 'render_template()'. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9535 + rule_id: QrUz49 + rv_id: 1263416 + url: + https://semgrep.dev/playground/r/WrTqKAz/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + version_id: WrTqKAz + shortlink: https://sg.run/Zv6o + source: + https://semgrep.dev/r/python.flask.security.audit.directly-returned-format-string.directly-returned-format-string + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-not-inside: return "..." + - pattern-either: + - pattern: return "...".format(...) + - pattern: return "..." % ... + - pattern: return "..." + ... + - pattern: return ... + "..." + - pattern: return f"...{...}..." + - patterns: + - pattern: return $X + - pattern-either: + - pattern-inside: "$X = \"...\".format(...)\n...\n" + - pattern-inside: "$X = \"...\" % ...\n...\n" + - pattern-inside: "$X = \"...\" + ...\n...\n" + - pattern-inside: "$X = ... + \"...\"\n...\n" + - pattern-inside: "$X = f\"...{...}...\"\n...\n" + - pattern-not-inside: "$X = \"...\"\n...\n" + pattern-sources: + - pattern-either: + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $PARAM, ...):\n ...\n" + - pattern: $PARAM + - pattern: "request.$FUNC.get(...)\n" + - pattern: "request.$FUNC(...)\n" + - pattern: request.$FUNC[...] + severity: WARNING +- id: python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + languages: + - python + message: Function `flask.url_for` with `_external=True` argument will generate URLs using the `Host` header of the + HTTP request, which may lead to security risks such as Host header injection + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-673: External Influence of Sphere Definition' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/latest/api/#flask.url_for + - https://portswigger.net/kb/issues/00500300_host-header-injection + semgrep.dev: + rule: + origin: community + r_id: 191541 + rule_id: JDU5oql + rv_id: 1263418 + url: + https://semgrep.dev/playground/r/K3TKk6n/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + version_id: K3TKk6n + shortlink: https://sg.run/gEGeR + source: https://semgrep.dev/r/python.flask.security.audit.flask-url-for-external-true.flask-url-for-external-true + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Other + patterns: + - pattern-not: flask.url_for(..., _external=False, ...) + - pattern-not: url_for(..., _external=False, ...) + - pattern-either: + - pattern: flask.url_for(..., _external=$VAR, ...) + - pattern: url_for(..., _external=$VAR, ...) + severity: WARNING +- id: python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + languages: + - python + message: The Flask secret key is used as salt in HashIDs. The HashID mechanism is not secure. By observing sufficient + HashIDs, the salt used to construct them can be recovered. This means the Flask secret key can be obtained by + attackers, through the HashIDs. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 – Cryptographic Failures + references: + - https://flask.palletsprojects.com/en/2.2.x/config/#SECRET_KEY + - http://carnage.github.io/2015/08/cryptanalysis-of-hashids + semgrep.dev: + rule: + origin: community + r_id: 72427 + rule_id: KxUX3z + rv_id: 946220 + url: + https://semgrep.dev/playground/r/0bT15Px/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + version_id: 0bT15Px + shortlink: https://sg.run/N0Rx + source: https://semgrep.dev/r/python.flask.security.hashids-with-flask-secret.hashids-with-flask-secret + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashids.Hashids(..., salt=flask.current_app.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids(flask.current_app.config['SECRET_KEY'], ...) + - patterns: + - pattern-inside: "$APP = flask.Flask(...)\n...\n" + - pattern-either: + - pattern: hashids.Hashids(..., salt=$APP.config['SECRET_KEY'], ...) + - pattern: hashids.Hashids($APP.config['SECRET_KEY'], ...) + severity: ERROR +- id: python.flask.security.injection.csv-writer-injection.csv-writer-injection + languages: + - python + message: Detected user input into a generated CSV file using the built-in `csv` module. If user data is used to + generate the data in this file, it is possible that an attacker could inject a formula when the CSV is imported into + a spreadsheet application that runs an attacker script, which could steal data from the importing user or, at worst, + install malware on the user's computer. `defusedcsv` is a drop-in replacement with the same API that will attempt to + mitigate formula injection attempts. You can use `defusedcsv` instead of `csv` to safely generate CSVs. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1236: Improper Neutralization of Formula Elements in a CSV File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://github.com/raphaelm/defusedcsv + - https://owasp.org/www-community/attacks/CSV_Injection + - https://web.archive.org/web/20220516052229/https://www.contextis.com/us/blog/comma-separated-vulnerabilities + semgrep.dev: + rule: + origin: community + r_id: 31146 + rule_id: L1UR2K + rv_id: 1263428 + url: + https://semgrep.dev/playground/r/jQTn50Y/python.flask.security.injection.csv-writer-injection.csv-writer-injection + version_id: jQTn50Y + shortlink: https://sg.run/JzqQ + source: https://semgrep.dev/r/python.flask.security.injection.csv-writer-injection.csv-writer-injection + subcategory: + - vuln + technology: + - python + - flask + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$WRITER = csv.writer(...)\n\n...\n\n$WRITER.$WRITE(...)\n" + - pattern: $WRITER.$WRITE(...) + - metavariable-regex: + metavariable: $WRITE + regex: ^(writerow|writerows|writeheader)$ + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.nan-injection.nan-injection + languages: + - python + message: Found user input going directly into typecast for bool(), float(), or complex(). This allows an attacker to + inject Python's not-a-number (NaN) into the typecast. This results in undefind behavior, particularly when doing + comparisons. Either cast to a different type, or add a guard checking for all capitalizations of the string 'nan'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://discuss.python.org/t/nan-breaks-min-max-and-sorting-functions-a-solution/2868 + - https://blog.bitdiscovery.com/2021/12/python-nan-injection/ + semgrep.dev: + rule: + origin: community + r_id: 18276 + rule_id: WAUdj7 + rv_id: 946222 + url: https://semgrep.dev/playground/r/qkT4j85/python.flask.security.injection.nan-injection.nan-injection + version_id: qkT4j85 + shortlink: https://sg.run/e598 + source: https://semgrep.dev/r/python.flask.security.injection.nan-injection.nan-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Improper Validation + mode: taint + pattern-sanitizers: + - not_conflicting: true + pattern: $ANYTHING(...) + pattern-sinks: + - pattern-either: + - pattern: float(...) + - pattern: bool(...) + - pattern: complex(...) + pattern-sources: + - pattern-either: + - pattern: flask.request.$SOMETHING.get(...) + - pattern: flask.request.$SOMETHING[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.os-system-injection.os-system-injection + languages: + - python + message: User data detected in os.system. This could be vulnerable to a command injection and should be avoided. If + this must be done, use the 'subprocess' module instead and pass the arguments as a list. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/www-community/attacks/Command_Injection + semgrep.dev: + rule: + origin: community + r_id: 9544 + rule_id: BYUN99 + rv_id: 1263429 + url: + https://semgrep.dev/playground/r/1QTypw7/python.flask.security.injection.os-system-injection.os-system-injection + version_id: 1QTypw7 + shortlink: https://sg.run/4xzz + source: https://semgrep.dev/r/python.flask.security.injection.os-system-injection.os-system-injection + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Command Injection + pattern-either: + - patterns: + - pattern: os.system(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n os.system(..., <... $ROUTEVAR + ...>, ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n os.system(..., <... $INTERM ...>, ...)\n" + - pattern: os.system(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W[...] ...>, ...) + - pattern: os.system(..., <... flask.request.$W(...) ...>, ...) + - pattern: os.system(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nos.system(<... $INTERM ...>)\n" + - pattern: os.system(...) + severity: ERROR +- id: python.flask.security.injection.path-traversal-open.path-traversal-open + languages: + - python + message: Found request data in a call to 'open'. Ensure the request data is validated or sanitized, otherwise it could + result in path traversal attacks. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9545 + rule_id: DbUpOQ + rv_id: 1263430 + url: + https://semgrep.dev/playground/r/9lT4b94/python.flask.security.injection.path-traversal-open.path-traversal-open + version_id: 9lT4b94 + shortlink: https://sg.run/PJRW + source: https://semgrep.dev/r/python.flask.security.injection.path-traversal-open.path-traversal-open + subcategory: + - audit + technology: + - flask + vulnerability_class: + - Path Traversal + pattern-either: + - patterns: + - pattern: open(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n open(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n with open(..., <... $ROUTEVAR + ...>, ...) as $FD:\n ...\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n open(..., <... $INTERM ...>, ...)\n" + - pattern: open(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: open(..., <... flask.request.$W[...] ...>, ...) + - pattern: open(..., <... flask.request.$W(...) ...>, ...) + - pattern: open(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nopen(<... $INTERM ...>, ...)\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nwith open(<... $INTERM ...>, ...) as $F:\n ...\n" + - pattern: open(...) + severity: ERROR +- id: python.flask.security.injection.raw-html-concat.raw-html-format + languages: + - python + message: Detected user input flowing into a manually constructed HTML string. You may be accidentally bypassing secure + methods of rendering HTML by manually constructing HTML and this could create a cross-site scripting vulnerability, + which could let attackers steal sensitive user data. To be sure this is safe, check that the HTML is rendered + safely. Otherwise, use templates (`flask.render_template`) which will safely render HTML instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/2.0.x/security/#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 14389 + rule_id: GdUrJv + rv_id: 1409401 + url: https://semgrep.dev/playground/r/RGTEN1l/python.flask.security.injection.raw-html-concat.raw-html-format + version_id: RGTEN1l + shortlink: https://sg.run/Pb7e + source: https://semgrep.dev/r/python.flask.security.injection.raw-html-concat.raw-html-format + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sanitizers: + - pattern: jinja2.escape(...) + - pattern: flask.escape(...) + - patterns: + - pattern: flask.render_template($TPL, ...) + - metavariable-regex: + metavariable: $TPL + regex: .*\.html + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: '"$HTMLSTR" % ...' + - pattern: '"$HTMLSTR".format(...)' + - pattern: '"$HTMLSTR" + ...' + - pattern: f"$HTMLSTR{...}..." + - patterns: + - pattern-inside: "$HTML = \"$HTMLSTR\"\n...\n" + - pattern-either: + - pattern: $HTML % ... + - pattern: $HTML.format(...) + - pattern: $HTML + ... + - metavariable-pattern: + language: generic + metavariable: $HTMLSTR + pattern: <$TAG ... + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: WARNING +- id: python.flask.security.injection.ssrf-requests.ssrf-requests + languages: + - python + message: Data from request object is passed to a new server-side request. This could lead to a server-side request + forgery (SSRF). To mitigate, ensure that schemes and hosts are validated against an allowlist, do not forward the + response to the user, and ensure proper authentication and transport-layer security in the proxied request. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://owasp.org/www-community/attacks/Server_Side_Request_Forgery + semgrep.dev: + rule: + origin: community + r_id: 9546 + rule_id: WAUoRx + rv_id: 1263432 + url: https://semgrep.dev/playground/r/rxTAKJn/python.flask.security.injection.ssrf-requests.ssrf-requests + version_id: rxTAKJn + shortlink: https://sg.run/J9LW + source: https://semgrep.dev/r/python.flask.security.injection.ssrf-requests.ssrf-requests + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Server-Side Request Forgery (SSRF) + pattern-either: + - patterns: + - pattern: requests.$FUNC(...) + - pattern-either: + - pattern-inside: "@$APP.$ROUTE_METHOD($ROUTE, ...)\ndef $ROUTE_FUNC(..., $ROUTEVAR, ...):\n ...\n requests.$FUNC(..., + <... $ROUTEVAR ...>, ...)\n" + - pattern-inside: "@$APP.$ROUTE_METHOD($ROUTE, ...)\ndef $ROUTE_FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... + $ROUTEVAR ...>\n ...\n requests.$FUNC(..., <... $INTERM ...>, ...)\n" + - metavariable-regex: + metavariable: $ROUTE_METHOD + regex: ^(route|get|post|put|delete|patch)$ + - pattern: requests.$FUNC(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W[...] ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W(...) ...>, ...) + - pattern: requests.$FUNC(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nrequests.$FUNC(<... $INTERM ...>, ...)\n" + - pattern: requests.$FUNC(...) + severity: ERROR +- id: python.flask.security.injection.subprocess-injection.subprocess-injection + languages: + - python + message: Detected user input entering a `subprocess` call unsafely. This could result in a command injection + vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them + to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the + command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a + dictionary to allowlist a set of commands. + metadata: + category: security + confidence: HIGH + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 31147 + rule_id: 8GU3qp + rv_id: 1263433 + url: + https://semgrep.dev/playground/r/bZT53gQ/python.flask.security.injection.subprocess-injection.subprocess-injection + version_id: bZT53gQ + shortlink: https://sg.run/5gW3 + source: https://semgrep.dev/r/python.flask.security.injection.subprocess-injection.subprocess-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - patterns: + - pattern: $DICT[$KEY] + - focus-metavariable: $KEY + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: subprocess.$FUNC(...) + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...", ...], ...) + - pattern-not-inside: "$CMD = [\"...\", ...]\n...\nsubprocess.$FUNC($CMD, ...)\n" + - patterns: + - pattern: subprocess.$FUNC(["$SHELL", "-c", ...], ...) + - metavariable-regex: + metavariable: $SHELL + regex: ^(sh|bash|ksh|csh|tcsh|zsh)$ + - patterns: + - pattern: subprocess.$FUNC(["$INTERPRETER", ...], ...) + - metavariable-regex: + metavariable: $INTERPRETER + regex: ^(python|python\d)$ + pattern-sources: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.tainted-sql-string.tainted-sql-string + languages: + - python + message: Detected user input used to manually construct a SQL string. This is usually bad practice because manual + construction could accidentally result in a SQL injection. An attacker could use a SQL injection to steal or modify + contents of the database. Instead, use a parameterized query which is available by default in most database engines. + Alternatively, consider using an object-relational mapper (ORM) such as SQLAlchemy which will protect your queries. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-704: Incorrect Type Conversion or Cast' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + - https://www.tutorialspoint.com/sqlalchemy/sqlalchemy_quick_guide.htm + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-more-specific-text-with-table-expression-literal-column-and-expression-column + semgrep.dev: + rule: + origin: community + r_id: 14702 + rule_id: YGUDKQ + rv_id: 1409402 + url: + https://semgrep.dev/playground/r/A8TEvb4/python.flask.security.injection.tainted-sql-string.tainted-sql-string + version_id: A8TEvb4 + shortlink: https://sg.run/JxZj + source: https://semgrep.dev/r/python.flask.security.injection.tainted-sql-string.tainted-sql-string + subcategory: + - vuln + technology: + - sqlalchemy + - flask + vulnerability_class: + - Improper Validation + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "\"$SQLSTR\" + ...\n" + - pattern: "\"$SQLSTR\" % ...\n" + - pattern: "\"$SQLSTR\".format(...)\n" + - pattern: "f\"$SQLSTR{...}...\"\n" + - metavariable-regex: + metavariable: $SQLSTR + regex: \s*(?i)(select|delete|insert|create|update|alter|drop)\b.* + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: ERROR +- id: python.flask.security.injection.tainted-url-host.tainted-url-host + languages: + - python + message: User data flows into the host portion of this manually-constructed URL. This could allow an attacker to send + data to their own server, potentially exposing sensitive data such as cookies or authorization information sent with + this request. They could also probe internal servers or other resources that the server running this code can + access. (This is called server-side request forgery, or SSRF.) Do not allow arbitrary hosts. Instead, create an + allowlist for approved hosts, or hardcode the correct host. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-918: Server-Side Request Forgery (SSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A10:2021 - Server-Side Request Forgery (SSRF) + - A01:2025 - Broken Access Control + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 14649 + rule_id: ReU3Wb + rv_id: 1409403 + url: https://semgrep.dev/playground/r/BjTy42w/python.flask.security.injection.tainted-url-host.tainted-url-host + version_id: BjTy42w + shortlink: https://sg.run/RXpK + source: https://semgrep.dev/r/python.flask.security.injection.tainted-url-host.tainted-url-host + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Server-Side Request Forgery (SSRF) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern: '"$URLSTR" % ...' + - metavariable-pattern: + language: generic + metavariable: $URLSTR + patterns: + - pattern-either: + - pattern: $SCHEME://%s + - pattern: $SCHEME://%r + - patterns: + - pattern: '"$URLSTR".format(...)' + - metavariable-pattern: + language: generic + metavariable: $URLSTR + pattern: $SCHEME:// { ... } + - patterns: + - pattern: '"$URLSTR" + ...' + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern: f"$URLSTR{...}..." + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + - patterns: + - pattern-inside: "$URL = \"$URLSTR\"\n...\n" + - pattern: $URL += ... + - metavariable-regex: + metavariable: $URLSTR + regex: .*://$ + pattern-sources: + - patterns: + - pattern-either: + - pattern: flask.request.$ANYTHING + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + severity: WARNING +- id: python.flask.security.injection.user-eval.eval-injection + languages: + - python + message: Detected user data flowing into eval. This is code injection and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/eval_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9547 + rule_id: 0oU54W + rv_id: 1263436 + url: https://semgrep.dev/playground/r/w8TRoB0/python.flask.security.injection.user-eval.eval-injection + version_id: w8TRoB0 + shortlink: https://sg.run/5QpX + source: https://semgrep.dev/r/python.flask.security.injection.user-eval.eval-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Code Injection + pattern-either: + - patterns: + - pattern: eval(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n eval(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n eval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W[...] ...>, ...) + - pattern: eval(..., <... flask.request.$W(...) ...>, ...) + - pattern: eval(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\neval(..., <... $INTERM ...>, ...)\n" + - pattern: eval(...) + severity: ERROR +- id: python.flask.security.injection.user-exec.exec-injection + languages: + - python + message: Detected user data flowing into exec. This is code injection and should be avoided. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://nedbatchelder.com/blog/201206/exec_really_is_dangerous.html + semgrep.dev: + rule: + origin: community + r_id: 9548 + rule_id: KxUbl2 + rv_id: 1263437 + url: https://semgrep.dev/playground/r/xyTjzD9/python.flask.security.injection.user-exec.exec-injection + version_id: xyTjzD9 + shortlink: https://sg.run/Ge42 + source: https://semgrep.dev/r/python.flask.security.injection.user-exec.exec-injection + subcategory: + - vuln + technology: + - flask + vulnerability_class: + - Code Injection + pattern-either: + - patterns: + - pattern: exec(...) + - pattern-either: + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n exec(..., <... $ROUTEVAR ...>, + ...)\n" + - pattern-inside: "@$APP.route($ROUTE, ...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n $INTERM = <... $ROUTEVAR ...>\n\ + \ ...\n exec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(..., <... flask.request.$W.get(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W[...] ...>, ...) + - pattern: exec(..., <... flask.request.$W(...) ...>, ...) + - pattern: exec(..., <... flask.request.$W ...>, ...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W.get(...) ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W[...] ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W(...) ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + - patterns: + - pattern-inside: "$INTERM = <... flask.request.$W ...>\n...\nexec(..., <... $INTERM ...>, ...)\n" + - pattern: exec(...) + severity: ERROR +- fix: "True\n" + id: python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + languages: + - python + message: Detected a Jinja2 environment with 'autoescaping' disabled. This is dangerous if you are rendering to a + browser because this allows for cross-site scripting (XSS) attacks. If you are in a web context, enable + 'autoescaping' by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' to only enable + automatic escaping for certain file extensions. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + semgrep.dev: + rule: + origin: community + r_id: 20039 + rule_id: QrU1Xg + rv_id: 1263448 + url: + https://semgrep.dev/playground/r/gETB7oN/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + version_id: gETB7oN + shortlink: https://sg.run/L2L7 + source: https://semgrep.dev/r/python.jinja2.security.audit.autoescape-disabled-false.incorrect-autoescape-disabled + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + subcategory: + - vuln + technology: + - jinja2 + vulnerability_class: + - Improper Encoding + patterns: + - pattern: jinja2.Environment(... , autoescape=$VAL, ...) + - pattern-not: jinja2.Environment(... , autoescape=True, ...) + - pattern-not: jinja2.Environment(... , autoescape=jinja2.select_autoescape(...), ...) + - focus-metavariable: $VAL + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, autoescape=True) + id: python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + languages: + - python + message: Detected a Jinja2 environment without autoescaping. Jinja2 does not autoescape by default. This is dangerous + if you are rendering to a browser because this allows for cross-site scripting (XSS) attacks. If you are in a web + context, enable autoescaping by setting 'autoescape=True.' You may also consider using 'jinja2.select_autoescape()' + to only enable automatic escaping for certain file extensions. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-116: Improper Encoding or Escaping of Output' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://jinja.palletsprojects.com/en/2.11.x/api/#basics + semgrep.dev: + rule: + origin: community + r_id: 20040 + rule_id: 3qULRx + rv_id: 1263449 + url: + https://semgrep.dev/playground/r/QkTGqje/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + version_id: QkTGqje + shortlink: https://sg.run/8kY4 + source: https://semgrep.dev/r/python.jinja2.security.audit.missing-autoescape-disabled.missing-autoescape-disabled + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b701_jinja2_autoescape_false.html + subcategory: + - vuln + technology: + - jinja2 + vulnerability_class: + - Improper Encoding + patterns: + - pattern-not: jinja2.Environment(..., autoescape=$VAL, ...) + - pattern: jinja2.Environment(...) + severity: WARNING +- id: python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + languages: + - python + message: 'Hardcoded JWT secret or private key is used. This is a Insufficiently Protected Credentials weakness: https://cwe.mitre.org/data/definitions/522.html + Consider using an appropriate security mechanism to protect the credentials (e.g. keeping secrets in environment variables)' + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-522: Insufficiently Protected Credentials' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A02:2017 - Broken Authentication + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + semgrep.dev: + rule: + origin: community + r_id: 9557 + rule_id: X5U8P5 + rv_id: 1263452 + url: https://semgrep.dev/playground/r/PkTR3X3/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + version_id: PkTR3X3 + shortlink: https://sg.run/l2E9 + source: https://semgrep.dev/r/python.jwt.security.jwt-hardcode.jwt-python-hardcoded-secret + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: "jwt.encode($_, \"...\", ...)\n" + severity: ERROR +- id: python.jwt.security.jwt-none-alg.jwt-python-none-alg + languages: + - python + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9558 + rule_id: j2UvKw + rv_id: 1263453 + url: https://semgrep.dev/playground/r/JdTzxYj/python.jwt.security.jwt-none-alg.jwt-python-none-alg + version_id: JdTzxYj + shortlink: https://sg.run/Yvp4 + source: https://semgrep.dev/r/python.jwt.security.jwt-none-alg.jwt-python-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "jwt.encode(...,algorithm=\"none\",...)\n" + - pattern: jwt.decode(...,algorithms=[...,"none",...],...) + severity: ERROR +- fix: "True\n" + id: python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + languages: + - python + message: Detected JWT token decoded with 'verify=False'. This bypasses any integrity checks for the token which means + the token could be tampered with by malicious actors. Ensure that the JWT token is verified. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-287: Improper Authentication' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A02:2017 - Broken Authentication + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://github.com/we45/Vulnerable-Flask-App/blob/752ee16087c0bfb79073f68802d907569a1f0df7/app/app.py#L96 + semgrep.dev: + rule: + origin: community + r_id: 9559 + rule_id: 10UKjo + rv_id: 1263454 + url: https://semgrep.dev/playground/r/5PTo12w/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + version_id: 5PTo12w + shortlink: https://sg.run/6nyB + source: https://semgrep.dev/r/python.jwt.security.unverified-jwt-decode.unverified-jwt-decode + subcategory: + - audit + technology: + - jwt + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - patterns: + - pattern: "jwt.decode(..., options={..., \"verify_signature\": $BOOL, ...}, ...)\n" + - metavariable-pattern: + metavariable: $BOOL + pattern: "False\n" + - focus-metavariable: $BOOL + - patterns: + - pattern: "$OPTS = {..., \"verify_signature\": $BOOL, ...}\n...\njwt.decode(..., options=$OPTS, ...)\n" + - metavariable-pattern: + metavariable: $BOOL + pattern: "False\n" + - focus-metavariable: $BOOL + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + languages: + - python + message: Detected subprocess function '$LOOP.subprocess_exec' with user controlled data. You may consider using + 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-eventloop.html#asyncio.loop.subprocess_exec + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27250 + rule_id: 7KUE1E + rv_id: 1263460 + url: + https://semgrep.dev/playground/r/WrTqKXz/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + version_id: WrTqKXz + shortlink: https://sg.run/Apjp + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-exec-tainted-env-args.dangerous-asyncio-exec-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - pattern-either: + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "...", ...) + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["...",...], ...) + - pattern: $LOOP.subprocess_exec(...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, "=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c",...) + - patterns: + - pattern-not: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", "...", ...], ...) + - pattern: $LOOP.subprocess_exec($PROTOCOL, ["=~/(sh|bash|ksh|csh|tcsh|zsh)/", "-c", ...], ...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + languages: + - python + message: Detected asyncio subprocess function with user controlled data. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.python.org/3/library/asyncio-subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27252 + rule_id: 8GU5q3 + rv_id: 1263462 + url: + https://semgrep.dev/playground/r/K3TKkDn/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + version_id: K3TKkDn + shortlink: https://sg.run/Dx8Y + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-asyncio-shell-tainted-env-args.dangerous-asyncio-shell-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: $LOOP.subprocess_shell($PROTOCOL, $CMD) + - pattern-inside: asyncio.subprocess.create_subprocess_shell($CMD, ...) + - pattern-inside: asyncio.create_subprocess_shell($CMD, ...) + - focus-metavariable: $CMD + - pattern-not-inside: "$CMD = \"...\"\n...\n" + - pattern-not: $LOOP.subprocess_shell($PROTOCOL, "...") + - pattern-not: asyncio.subprocess.create_subprocess_shell("...", ...) + - pattern-not: asyncio.create_subprocess_shell("...", ...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + languages: + - python + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if + external data can reach this function call because it allows a malicious actor to run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27254 + rule_id: QrUG72 + rv_id: 1263464 + url: + https://semgrep.dev/playground/r/l4TJRK9/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + version_id: l4TJRK9 + shortlink: https://sg.run/0Bgv + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-code-run-tainted-env-args.dangerous-interactive-code-run-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$X = code.InteractiveConsole(...)\n...\n" + - pattern-inside: "$X = code.InteractiveInterpreter(...)\n...\n" + - pattern-either: + - pattern-inside: "$X.push($PAYLOAD,...)\n" + - pattern-inside: "$X.runsource($PAYLOAD,...)\n" + - pattern-inside: "$X.runcode(code.compile_command($PAYLOAD),...)\n" + - pattern-inside: "$PL = code.compile_command($PAYLOAD,...)\n...\n$X.runcode($PL,...)\n" + - pattern: $PAYLOAD + - pattern-not: "$X.push(\"...\",...)\n" + - pattern-not: "$X.runsource(\"...\",...)\n" + - pattern-not: "$X.runcode(code.compile_command(\"...\"),...)\n" + - pattern-not: "$PL = code.compile_command(\"...\",...)\n...\n$X.runcode($PL,...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27256 + rule_id: 4bUEAY + rv_id: 1263466 + url: + https://semgrep.dev/playground/r/6xT29l6/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + version_id: 6xT29l6 + shortlink: https://sg.run/qL6z + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-os-exec-tainted-env-args.dangerous-os-exec-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27258 + rule_id: JDUz34 + rv_id: 1263468 + url: + https://semgrep.dev/playground/r/zyTb2wn/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + version_id: zyTb2wn + shortlink: https://sg.run/Y3Ke + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-spawn-process-tainted-env-args.dangerous-spawn-process-tainted-env-args + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: + python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + languages: + - python + message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run + arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27260 + rule_id: GdUkxO + rv_id: 1409404 + url: + https://semgrep.dev/playground/r/DkTwBzO/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + version_id: DkTwBzO + shortlink: https://sg.run/oLl9 + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-subinterpreters-run-string-tainted-env-args.dangerous-subinterpreters-run-string-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-inside: "_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)\n" + - pattern-not: "_xxsubinterpreters.run_string($ID, \"...\", ...)\n" + - pattern: $PAYLOAD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + languages: + - python + message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to + perform command injection. You may consider using 'shlex.quote()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27262 + rule_id: AbUgrZ + rv_id: 1263472 + url: + https://semgrep.dev/playground/r/jQTn54Y/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + version_id: jQTn54Y + shortlink: https://sg.run/pLGg + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-subprocess-use-tainted-env-args.dangerous-subprocess-use-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sanitizers: + - pattern: shlex.quote(...) + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + languages: + - python + message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use + the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection + vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27264 + rule_id: DbUR9g + rv_id: 1263474 + url: + https://semgrep.dev/playground/r/9lT4bG4/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + version_id: 9lT4bG4 + shortlink: https://sg.run/XR2K + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-system-call-tainted-env-args.dangerous-system-call-tainted-env-args + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: "$X = __import__(\"os\")\n...\n$X.system(...)\n" + - pattern: "$X = __import__(\"os\")\n...\ngetattr($X, \"system\")(...)\n" + - pattern: "$X = getattr(os, \"system\")\n...\n$X(...)\n" + - pattern: "$X = __import__(\"os\")\n...\n$Y = getattr($X, \"system\")\n...\n$Y(...)\n" + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: + python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + languages: + - python + message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to + run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27266 + rule_id: 0oUK7N + rv_id: 1263476 + url: + https://semgrep.dev/playground/r/rxTAKpn/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + version_id: rxTAKpn + shortlink: https://sg.run/1DLw + source: + https://semgrep.dev/r/python.lang.security.audit.dangerous-testcapi-run-in-subinterp-tainted-env-args.dangerous-testcapi-run-in-subinterp-tainted-env-args + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "_testcapi.run_in_subinterp($PAYLOAD, ...)\n" + - pattern-inside: "test.support.run_in_subinterp($PAYLOAD, ...)\n" + - pattern: $PAYLOAD + - pattern-not: "_testcapi.run_in_subinterp(\"...\", ...)\n" + - pattern-not: "test.support.run_in_subinterp(\"...\", ...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: os.environ + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv + - pattern: sys.orig_argv + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: WARNING +- id: python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + languages: + - python + message: These permissions `$BITS` are widely permissive and grant access to more people than may be necessary. A good + default is `0o644` which gives read and write access to yourself and read access to everyone else. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-276: Incorrect Default Permissions' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 13594 + rule_id: zdUYqR + rv_id: 1263482 + url: + https://semgrep.dev/playground/r/O9Tpxqr/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + version_id: O9Tpxqr + shortlink: https://sg.run/AXY4 + source: https://semgrep.dev/r/python.lang.security.audit.insecure-file-permissions.insecure-file-permissions + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Improper Authorization + patterns: + - pattern-inside: os.$METHOD(...) + - metavariable-pattern: + metavariable: $METHOD + patterns: + - pattern-either: + - pattern: chmod + - pattern: lchmod + - pattern: fchmod + - pattern-either: + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-comparison: + comparison: $BITS >= 0o650 and $BITS < 0o100000 + metavariable: $BITS + - patterns: + - pattern: os.$METHOD($FILE, $BITS) + - metavariable-comparison: + comparison: $BITS >= 0o100650 + metavariable: $BITS + - patterns: + - pattern: os.$METHOD($FILE, $BITS, ...) + - metavariable-pattern: + metavariable: $BITS + patterns: + - pattern-either: + - pattern: <... stat.S_IWGRP ...> + - pattern: <... stat.S_IXGRP ...> + - pattern: <... stat.S_IWOTH ...> + - pattern: <... stat.S_IXOTH ...> + - pattern: <... stat.S_IRWXO ...> + - pattern: <... stat.S_IRWXG ...> + - patterns: + - pattern: os.$METHOD($FILE, $EXPR | $MOD, ...) + - metavariable-comparison: + comparison: $MOD == 0o111 + metavariable: $MOD + severity: WARNING +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: + python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. + metadata: + asvs: + control_id: 9.2.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9651 + rule_id: lBU9BZ + rv_id: 1263484 + url: + https://semgrep.dev/playground/r/vdT06wb/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + version_id: vdT06wb + shortlink: https://sg.run/Bk5W + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-http-in-with-context.request-session-http-in-with-context + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-inside: "with requests.Session(...) as $SESSION:\n ...\n" + - pattern-either: + - pattern: $SESSION.$W($SINK, ...) + - pattern: $SESSION.request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted. Use 'https://' instead. + metadata: + asvs: + control_id: 9.1.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9652 + rule_id: YGURXw + rv_id: 1263485 + url: + https://semgrep.dev/playground/r/d6Tyx02/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + version_id: d6Tyx02 + shortlink: https://sg.run/DoBY + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-session-with-http.request-session-with-http + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.Session(...).$W($SINK, ...) + - pattern: requests.Session(...).request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- fix-regex: + count: 1 + regex: '[Hh][Tt][Tt][Pp]://' + replacement: https:// + id: python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + languages: + - python + message: Detected a request using 'http://'. This request will be unencrypted, and attackers could listen into traffic + on the network and be able to obtain sensitive information. Use 'https://' instead. + metadata: + asvs: + control_id: 9.1.1 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v92-server-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9653 + rule_id: 6JUjpG + rv_id: 1263486 + url: + https://semgrep.dev/playground/r/ZRTKA9v/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + version_id: ZRTKA9v + shortlink: https://sg.run/W8J4 + source: + https://semgrep.dev/r/python.lang.security.audit.insecure-transport.requests.request-with-http.request-with-http + subcategory: + - audit + technology: + - requests + vulnerability_class: + - Mishandled Sensitive Information + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: requests.$W($SINK, ...) + - pattern: requests.request($METHOD, $SINK, ...) + - pattern: requests.Request($METHOD, $SINK, ...) + - focus-metavariable: $SINK + pattern-sources: + - patterns: + - pattern: "\"$URL\"\n" + - metavariable-pattern: + language: regex + metavariable: $URL + patterns: + - pattern-regex: http:// + - pattern-not-regex: .*://localhost + - pattern-not-regex: .*://127\.0\.0\.1 + severity: INFO +- id: python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + languages: + - python + message: Detected a python logger call with a potential hardcoded secret $FORMAT_STRING being logged. This may lead to + secret credentials being exposed. Make sure that the logger is not logging sensitive information. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-532: Insertion of Sensitive Information into Log File' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A09:2021 - Security Logging and Monitoring Failures + - A09:2025 - Security Logging & Alerting Failures + references: + - https://owasp.org/Top10/A09_2021-Security_Logging_and_Monitoring_Failures + semgrep.dev: + rule: + origin: community + r_id: 9668 + rule_id: x8UnJk + rv_id: 1263501 + url: + https://semgrep.dev/playground/r/A8TgdOR/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + version_id: A8TgdOR + shortlink: https://sg.run/ydNx + source: + https://semgrep.dev/r/python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + patterns: + - pattern: "$LOGGER_OBJ.$LOGGER_CALL($FORMAT_STRING,...)\n" + - metavariable-regex: + metavariable: $LOGGER_OBJ + regex: (?i)(_logger|logger|self.logger|log) + - metavariable-regex: + metavariable: $LOGGER_CALL + regex: (debug|info|warn|warning|error|exception|critical) + - metavariable-regex: + metavariable: $FORMAT_STRING + regex: (?i).*(api.key|secret|credential|token|password).*\%s.* + severity: WARNING +- id: python.lang.security.audit.md5-used-as-password.md5-used-as-password + languages: + - python + message: It looks like MD5 is used as a password hash. MD5 is not considered a secure password hash because it can be + cracked by an attacker in a short amount of time. Use a suitable password hashing function such as scrypt. You can + use `hashlib.scrypt`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + - https://security.stackexchange.com/questions/211/how-to-securely-hash-passwords + - https://github.com/returntocorp/semgrep-rules/issues/1609 + - https://docs.python.org/3/library/hashlib.html#hashlib.scrypt + semgrep.dev: + rule: + origin: community + r_id: 14703 + rule_id: 6JU1w1 + rv_id: 1263504 + url: + https://semgrep.dev/playground/r/WrTqKDz/python.lang.security.audit.md5-used-as-password.md5-used-as-password + version_id: WrTqKDz + shortlink: https://sg.run/5DwD + source: https://semgrep.dev/r/python.lang.security.audit.md5-used-as-password.md5-used-as-password + subcategory: + - vuln + technology: + - pycryptodome + - hashlib + - md5 + vulnerability_class: + - Cryptographic Issues + mode: taint + pattern-sinks: + - patterns: + - pattern: $FUNCTION(...) + - metavariable-regex: + metavariable: $FUNCTION + regex: (?i)(.*password.*) + pattern-sources: + - patterns: + - pattern-either: + - pattern: hashlib.md5 + - pattern: hashlib.new(..., name="MD5", ...) + - pattern: Cryptodome.Hash.MD5 + - pattern: Crypto.Hash.MD5 + - pattern: cryptography.hazmat.primitives.hashes.MD5 + severity: WARNING +- id: python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + languages: + - python + message: Running `socket.bind` to 0.0.0.0, or empty string could unexpectedly expose the server publicly as it binds + to all available interfaces. Consider instead getting correct address from an environment variable or configuration + file. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-200: Exposure of Sensitive Information to an Unauthorized Actor' + cwe2021-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9669 + rule_id: OrU3og + rv_id: 1263505 + url: + https://semgrep.dev/playground/r/0bTKzDL/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + version_id: 0bTKzDL + shortlink: https://sg.run/rdln + source: https://semgrep.dev/r/python.lang.security.audit.network.bind.avoid-bind-to-all-interfaces + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"0.0.0.0\", ...))\n" + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"::\", ...))\n" + - pattern: "$S = socket.socket(...)\n...\n$S.bind((\"\", ...))\n" + severity: INFO +- id: python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + languages: + - python + message: certificate verification explicitly disabled, insecure connections possible + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures + semgrep.dev: + rule: + origin: community + r_id: 9670 + rule_id: eqU87k + rv_id: 1263506 + url: + https://semgrep.dev/playground/r/K3TKkZn/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + version_id: K3TKkZn + shortlink: https://sg.run/b7yp + source: https://semgrep.dev/r/python.lang.security.audit.network.disabled-cert-validation.disabled-cert-validation + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: urllib3.PoolManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.ProxyManager(..., cert_reqs=$REQS, ...) + - pattern: urllib3.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connectionpool.HTTPSConnectionPool(..., cert_reqs=$REQS, ...) + - pattern: urllib3.connection_from_url(..., cert_reqs=$REQS, ...) + - pattern: urllib3.proxy_from_url(..., cert_reqs=$REQS, ...) + - pattern: $CONTEXT.wrap_socket(..., cert_reqs=$REQS, ...) + - pattern: ssl.wrap_socket(..., cert_reqs=$REQS, ...) + - metavariable-regex: + metavariable: $REQS + regex: + (NONE|CERT_NONE|CERT_OPTIONAL|ssl\.CERT_NONE|ssl\.CERT_OPTIONAL|\'NONE\'|\"NONE\"|\'OPTIONAL\'|\"OPTIONAL\") + severity: ERROR +- id: python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + languages: + - python + message: Detected HTTPConnectionPool. This will transmit data in cleartext. It is recommended to use + HTTPSConnectionPool instead for to encrypt communications. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-319: Cleartext Transmission of Sensitive Information' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://urllib3.readthedocs.io/en/1.2.1/pools.html#urllib3.connectionpool.HTTPSConnectionPool + semgrep.dev: + rule: + origin: community + r_id: 9671 + rule_id: v8UnWQ + rv_id: 1263507 + url: + https://semgrep.dev/playground/r/qkTR7E1/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + version_id: qkTR7E1 + shortlink: https://sg.run/N4Np + source: https://semgrep.dev/r/python.lang.security.audit.network.http-not-https-connection.http-not-https-connection + subcategory: + - audit + technology: + - python + vulnerability_class: + - Mishandled Sensitive Information + pattern-either: + - pattern: urllib3.HTTPConnectionPool(...) + - pattern: urllib3.connectionpool.HTTPConnectionPool(...) + severity: ERROR +- id: python.lang.security.audit.sha224-hash.sha224-hash + languages: + - python + message: This code uses a 224-bit hash function, which is deprecated or disallowed in some security policies. Consider + updating to a stronger hash function such as SHA-384 or higher to ensure compliance and security. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf + - https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography + semgrep.dev: + rule: + origin: community + r_id: 151752 + rule_id: BYUX0y9 + rv_id: 1263511 + url: https://semgrep.dev/playground/r/5PTo1QL/python.lang.security.audit.sha224-hash.sha224-hash + version_id: 5PTo1QL + shortlink: https://sg.run/Db1Yv + source: https://semgrep.dev/r/python.lang.security.audit.sha224-hash.sha224-hash + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: hashlib.sha224(...) + - pattern: hashlib.sha3_224(...) + severity: WARNING +- id: python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + languages: + - python + message: "'ssl.wrap_socket()' is deprecated. This function creates an insecure socket without server name indication or + hostname matching. Instead, create an SSL context using 'ssl.SSLContext()' and use that to wrap a socket." + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://docs.python.org/3/library/ssl.html#ssl.wrap_socket + - https://docs.python.org/3/library/ssl.html#ssl.SSLContext.wrap_socket + semgrep.dev: + rule: + origin: community + r_id: 9645 + rule_id: BYUN2e + rv_id: 1263516 + url: + https://semgrep.dev/playground/r/DkTRbgn/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + version_id: DkTRbgn + shortlink: https://sg.run/PJOY + source: https://semgrep.dev/r/python.lang.security.audit.ssl-wrap-socket-is-deprecated.ssl-wrap-socket-is-deprecated + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern: ssl.wrap_socket(...) + severity: WARNING +- fix: "False\n" + id: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + languages: + - python + message: Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the + command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier + for a malicious actor to execute commands. Use 'shell=False' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + semgrep.dev: + rule: + origin: community + r_id: 9646 + rule_id: DbUpz2 + rv_id: 1263518 + url: + https://semgrep.dev/playground/r/0bTKzDK/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + version_id: 0bTKzDK + shortlink: https://sg.run/J92w + source: https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html + subcategory: + - secure default + technology: + - python + vulnerability_class: + - Command Injection + patterns: + - pattern: subprocess.$FUNC(..., shell=$TRUE, ...) + - metavariable-pattern: + metavariable: $TRUE + pattern: "True \n" + - pattern-not: subprocess.$FUNC("...", shell=True, ...) + - focus-metavariable: $TRUE + severity: ERROR +- id: python.lang.security.audit.weak-ssl-version.weak-ssl-version + languages: + - python + message: An insecure SSL version was detected. TLS versions 1.0, 1.1, and all SSL versions are considered weak + encryption and are deprecated. Use 'ssl.PROTOCOL_TLSv1_2' or higher. + metadata: + asvs: + control_id: 9.1.3 Weak TLS + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x17-V9-Communications.md#v91-client-communications-security-requirements + section: V9 Communications Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-326: Inadequate Encryption Strength' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc7568 + - https://tools.ietf.org/id/draft-ietf-tls-oldversions-deprecate-02.html + - https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_TLSv1_2 + semgrep.dev: + rule: + origin: community + r_id: 9649 + rule_id: KxUbNG + rv_id: 1263520 + url: https://semgrep.dev/playground/r/qkTR7Ev/python.lang.security.audit.weak-ssl-version.weak-ssl-version + version_id: qkTR7Ev + shortlink: https://sg.run/RoZO + source: https://semgrep.dev/r/python.lang.security.audit.weak-ssl-version.weak-ssl-version + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/insecure_ssl_tls.py#L30 + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: ssl.PROTOCOL_SSLv2 + - pattern: ssl.PROTOCOL_SSLv3 + - pattern: ssl.PROTOCOL_TLSv1 + - pattern: ssl.PROTOCOL_TLSv1_1 + - pattern: pyOpenSSL.SSL.SSLv2_METHOD + - pattern: pyOpenSSL.SSL.SSLv23_METHOD + - pattern: pyOpenSSL.SSL.SSLv3_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_METHOD + - pattern: pyOpenSSL.SSL.TLSv1_1_METHOD + severity: WARNING +- id: python.lang.security.dangerous-code-run.dangerous-interactive-code-run + languages: + - python + message: Found user controlled data inside InteractiveConsole/InteractiveInterpreter method. This is dangerous if + external data can reach this function call because it allows a malicious actor to run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27267 + rule_id: KxUKzx + rv_id: 1263521 + url: + https://semgrep.dev/playground/r/l4TJRgo/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + version_id: l4TJRgo + shortlink: https://sg.run/9pRY + source: https://semgrep.dev/r/python.lang.security.dangerous-code-run.dangerous-interactive-code-run + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$X = code.InteractiveConsole(...)\n...\n" + - pattern-inside: "$X = code.InteractiveInterpreter(...)\n...\n" + - pattern-either: + - pattern: "$X.push($PAYLOAD,...)\n" + - pattern: "$X.runsource($PAYLOAD,...)\n" + - pattern: "$X.runcode(code.compile_command($PAYLOAD),...)\n" + - pattern: "$PL = code.compile_command($PAYLOAD,...)\n...\n$X.runcode($PL,...)\n" + - focus-metavariable: $PAYLOAD + - pattern-not: "$X.push(\"...\",...)\n" + - pattern-not: "$X.runsource(\"...\",...)\n" + - pattern-not: "$X.runcode(code.compile_command(\"...\"),...)\n" + - pattern-not: "$PL = code.compile_command(\"...\",...)\n...\n$X.runcode($PL,...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- id: python.lang.security.dangerous-os-exec.dangerous-os-exec + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27268 + rule_id: qNUR13 + rv_id: 1263523 + url: https://semgrep.dev/playground/r/6xT29rz/python.lang.security.dangerous-os-exec.dangerous-os-exec + version_id: 6xT29rz + shortlink: https://sg.run/yL9x + source: https://semgrep.dev/r/python.lang.security.dangerous-os-exec.dangerous-os-exec + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD("...", ...) + - pattern: os.$METHOD(...) + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe|execv|execve|execvp|execvpe) + - patterns: + - pattern-not: os.$METHOD("...", [$PATH,"...","...",...],...) + - pattern-inside: os.$METHOD($BASH,[$PATH,"-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execv|execve|execvp|execvpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD("...", $PATH, "...", "...",...) + - pattern-inside: os.$METHOD($BASH, $PATH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (execl|execle|execlp|execlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-spawn-process.dangerous-spawn-process + languages: + - python + message: Found user controlled content when spawning a process. This is dangerous because it allows a malicious actor + to execute commands. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27269 + rule_id: lBUJrn + rv_id: 1263524 + url: + https://semgrep.dev/playground/r/o5TbDO5/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + version_id: o5TbDO5 + shortlink: https://sg.run/r8Zn + source: https://semgrep.dev/r/python.lang.security.dangerous-spawn-process.dangerous-spawn-process + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ...) + - pattern-inside: os.$METHOD($MODE, $CMD, ...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: + (spawnl|spawnle|spawnlp|spawnlpe|spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp|startfile) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", ["...","...",...], ...) + - pattern-inside: os.$METHOD($MODE, $BASH, ["-c",$CMD,...],...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnv|spawnve|spawnvp|spawnvp|spawnvpe|posix_spawn|posix_spawnp) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + - patterns: + - pattern-not: os.$METHOD($MODE, "...", "...", "...", ...) + - pattern-inside: os.$METHOD($MODE, $BASH, "-c", $CMD,...) + - pattern: $CMD + - metavariable-regex: + metavariable: $METHOD + regex: (spawnl|spawnle|spawnlp|spawnlpe) + - metavariable-regex: + metavariable: $BASH + regex: (.*)(sh|bash|ksh|csh|tcsh|zsh) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - pattern: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + - patterns: + - pattern-either: + - pattern: os.environ['$ANYTHING'] + - pattern: os.environ.get('$FOO', ...) + - pattern: os.environb['$ANYTHING'] + - pattern: os.environb.get('$FOO', ...) + - pattern: os.getenv('$ANYTHING', ...) + - pattern: os.getenvb('$ANYTHING', ...) + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: sys.argv[...] + - pattern: sys.orig_argv[...] + - patterns: + - pattern-inside: "$PARSER = argparse.ArgumentParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-inside: "$PARSER = optparse.OptionParser(...)\n...\n" + - pattern-inside: "$ARGS = $PARSER.parse_args()\n" + - pattern: <... $ARGS ...> + - patterns: + - pattern-either: + - pattern-inside: "$OPTS, $ARGS = getopt.getopt(...)\n...\n" + - pattern-inside: "$OPTS, $ARGS = getopt.gnu_getopt(...)\n...\n" + - pattern-either: + - patterns: + - pattern-inside: "for $O, $A in $OPTS:\n ...\n" + - pattern: $A + - pattern: $ARGS + severity: ERROR +- id: python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + languages: + - python + message: Found user controlled content in `run_string`. This is dangerous because it allows a malicious actor to run + arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://bugs.python.org/issue43472 + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27270 + rule_id: PeURWr + rv_id: 1263525 + url: + https://semgrep.dev/playground/r/zyTb2OX/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + version_id: zyTb2OX + shortlink: https://sg.run/bPop + source: + https://semgrep.dev/r/python.lang.security.dangerous-subinterpreters-run-string.dangerous-subinterpreters-run-string + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern: "_xxsubinterpreters.run_string($ID, $PAYLOAD, ...)\n" + - pattern-not: "_xxsubinterpreters.run_string($ID, \"...\", ...)\n" + - focus-metavariable: $PAYLOAD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- id: python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + languages: + - python + message: Detected subprocess function '$FUNC' with user controlled data. A malicious actor could leverage this to + perform command injection. You may consider using 'shlex.escape()'. + metadata: + asvs: + control_id: 5.3.8 OS Command Injection + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v53-output-encoding-and-injection-prevention-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess + - https://docs.python.org/3/library/subprocess.html + - https://docs.python.org/3/library/shlex.html + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27271 + rule_id: JDUz3R + rv_id: 1263526 + url: + https://semgrep.dev/playground/r/pZT038J/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + version_id: pZT038J + shortlink: https://sg.run/NWxp + source: https://semgrep.dev/r/python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - patterns: + - pattern-not: subprocess.$FUNC("...", ...) + - pattern-not: subprocess.$FUNC(["...",...], ...) + - pattern-not: subprocess.$FUNC(("...",...), ...) + - pattern-not: subprocess.CalledProcessError(...) + - pattern-not: subprocess.SubprocessError(...) + - pattern: subprocess.$FUNC($CMD, ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...) + - pattern: subprocess.$FUNC("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD], ...) + - pattern: subprocess.$FUNC(("=~/(sh|bash|ksh|csh|tcsh|zsh)/","-c", $CMD), ...) + - patterns: + - pattern-not: subprocess.$FUNC("=~/(python)/","...",...) + - pattern: subprocess.$FUNC("=~/(python)/", $CMD) + - patterns: + - pattern-not: subprocess.$FUNC(["=~/(python)/","...",...],...) + - pattern-not: subprocess.$FUNC(("=~/(python)/","...",...),...) + - pattern-either: + - pattern: subprocess.$FUNC(["=~/(python)/", $CMD],...) + - pattern: subprocess.$FUNC(("=~/(python)/", $CMD),...) + - focus-metavariable: $CMD + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-system-call.dangerous-system-call + languages: + - python + message: Found user-controlled data used in a system call. This could allow a malicious actor to execute commands. Use + the 'subprocess' module instead, which is easier to use without accidentally exposing a command injection + vulnerability. + metadata: + asvs: + control_id: 5.2.4 Dyanmic Code Execution Features + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v52-sanitization-and-sandboxing-requirements + section: 'V5: Validation, Sanitization and Encoding Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27272 + rule_id: 5rUoP1 + rv_id: 1263527 + url: https://semgrep.dev/playground/r/2KTv2Zn/python.lang.security.dangerous-system-call.dangerous-system-call + version_id: 2KTv2Zn + shortlink: https://sg.run/k0W7 + source: https://semgrep.dev/r/python.lang.security.dangerous-system-call.dangerous-system-call + source-rule-url: https://bandit.readthedocs.io/en/latest/plugins/b605_start_process_with_a_shell.html + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Command Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-not: os.$W("...", ...) + - pattern-either: + - pattern: os.system(...) + - pattern: getattr(os, "system")(...) + - pattern: __import__("os").system(...) + - pattern: getattr(__import__("os"), "system")(...) + - pattern: "$X = __import__(\"os\")\n...\n$X.system(...)\n" + - pattern: "$X = __import__(\"os\")\n...\ngetattr($X, \"system\")(...)\n" + - pattern: "$X = getattr(os, \"system\")\n...\n$X(...)\n" + - pattern: "$X = __import__(\"os\")\n...\n$Y = getattr($X, \"system\")\n...\n$Y(...)\n" + - pattern: os.popen(...) + - pattern: os.popen2(...) + - pattern: os.popen3(...) + - pattern: os.popen4(...) + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + languages: + - python + message: Found user controlled content in `run_in_subinterp`. This is dangerous because it allows a malicious actor to + run arbitrary Python code. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')" + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://semgrep.dev/docs/cheat-sheets/python-command-injection/ + semgrep.dev: + rule: + origin: community + r_id: 27273 + rule_id: GdUkxR + rv_id: 1263528 + url: + https://semgrep.dev/playground/r/X0Tzy1e/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + version_id: X0Tzy1e + shortlink: https://sg.run/wLpY + source: + https://semgrep.dev/r/python.lang.security.dangerous-testcapi-run-in-subinterp.dangerous-testcapi-run-in-subinterp + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Code Injection + mode: taint + options: + symbolic_propagation: true + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "_testcapi.run_in_subinterp($PAYLOAD, ...)\n" + - pattern: "test.support.run_in_subinterp($PAYLOAD, ...)\n" + - focus-metavariable: $PAYLOAD + - pattern-not: "_testcapi.run_in_subinterp(\"...\", ...)\n" + - pattern-not: "test.support.run_in_subinterp(\"...\", ...)\n" + pattern-sources: + - patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: flask.request.form.get(...) + - pattern: flask.request.form[...] + - pattern: flask.request.args.get(...) + - pattern: flask.request.args[...] + - pattern: flask.request.values.get(...) + - pattern: flask.request.values[...] + - pattern: flask.request.cookies.get(...) + - pattern: flask.request.cookies[...] + - pattern: flask.request.stream + - pattern: flask.request.headers.get(...) + - pattern: flask.request.headers[...] + - pattern: flask.request.data + - pattern: flask.request.full_path + - pattern: flask.request.url + - pattern: flask.request.json + - pattern: flask.request.get_json() + - pattern: flask.request.view_args.get(...) + - pattern: flask.request.view_args[...] + - patterns: + - pattern-inside: "@$APP.route(...)\ndef $FUNC(..., $ROUTEVAR, ...):\n ...\n" + - focus-metavariable: $ROUTEVAR + - patterns: + - pattern-inside: "def $FUNC(request, ...):\n ...\n" + - pattern-either: + - pattern: request.$PROPERTY.get(...) + - pattern: request.$PROPERTY[...] + - patterns: + - pattern-either: + - pattern-inside: "@rest_framework.decorators.api_view(...)\ndef $FUNC($REQ, ...):\n ...\n" + - patterns: + - pattern-either: + - pattern-inside: "class $VIEW(..., rest_framework.views.APIView, ...):\n ...\n" + - pattern-inside: "class $VIEW(..., rest_framework.generics.GenericAPIView, ...):\n ... \ + \ \n" + - pattern-inside: "def $METHOD(self, $REQ, ...):\n ...\n" + - metavariable-regex: + metavariable: $METHOD + regex: (get|post|put|patch|delete|head) + - pattern-either: + - pattern: $REQ.POST.get(...) + - pattern: $REQ.POST[...] + - pattern: $REQ.FILES.get(...) + - pattern: $REQ.FILES[...] + - pattern: $REQ.DATA.get(...) + - pattern: $REQ.DATA[...] + - pattern: $REQ.QUERY_PARAMS.get(...) + - pattern: $REQ.QUERY_PARAMS[...] + - pattern: $REQ.data.get(...) + - pattern: $REQ.data[...] + - pattern: $REQ.query_params.get(...) + - pattern: $REQ.query_params[...] + - pattern: $REQ.content_type + - pattern: $REQ.content_type + - pattern: $REQ.stream + - pattern: $REQ.stream + - patterns: + - pattern-either: + - pattern-inside: "class $SERVER(..., http.server.BaseHTTPRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.StreamRequestHandler, ...):\n ...\n" + - pattern-inside: "class $SERVER(..., http.server.DatagramRequestHandler, ...):\n ...\n" + - pattern-either: + - pattern: self.requestline + - pattern: self.path + - pattern: self.headers[...] + - pattern: self.headers.get(...) + - pattern: self.rfile + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: WARNING +- fix-regex: + count: 1 + regex: unsafe_load + replacement: safe_load + id: python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + languages: + - python + message: Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, + and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the + YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow + the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` + or `yaml.SafeLoader` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation + - https://nvd.nist.gov/vuln/detail/CVE-2017-18342 + semgrep.dev: + rule: + origin: community + r_id: 9673 + rule_id: ZqU5jZ + rv_id: 1263530 + url: + https://semgrep.dev/playground/r/1QTyprw/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + version_id: 1QTyprw + shortlink: https://sg.run/we9Y + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load + subcategory: + - audit + technology: + - pyyaml + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern-inside: "import yaml\n...\n" + - pattern-not-inside: "$YAML = ruamel.yaml.YAML(...)\n...\n" + - pattern-either: + - pattern: yaml.unsafe_load(...) + - pattern: yaml.load(..., Loader=yaml.Loader, ...) + - pattern: yaml.load(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load(..., Loader=yaml.CLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.Loader, ...) + - pattern: yaml.load_all(..., Loader=yaml.UnsafeLoader, ...) + - pattern: yaml.load_all(..., Loader=yaml.CLoader, ...) + severity: ERROR +- id: python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + languages: + - python + message: Avoid using unsafe `ruamel.yaml.YAML()`. `ruamel.yaml.YAML` can create arbitrary Python objects. A malicious + actor could exploit this to run arbitrary code. Use `YAML(typ='rt')` or `YAML(typ='safe')` instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://yaml.readthedocs.io/en/latest/basicuse.html?highlight=typ + semgrep.dev: + rule: + origin: community + r_id: 9674 + rule_id: nJUzqK + rv_id: 1263531 + url: + https://semgrep.dev/playground/r/9lT4bvG/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + version_id: 9lT4bvG + shortlink: https://sg.run/x1rz + source: https://semgrep.dev/r/python.lang.security.deserialization.avoid-unsafe-ruamel.avoid-unsafe-ruamel + subcategory: + - audit + technology: + - ruamel.yaml + vulnerability_class: + - 'Insecure Deserialization ' + pattern-either: + - pattern: ruamel.yaml.YAML(..., typ='unsafe', ...) + - pattern: ruamel.yaml.YAML(..., typ='base', ...) + severity: ERROR +- id: python.lang.security.deserialization.pickle.avoid-shelve + languages: + - python + message: Avoid using `shelve`, which uses `pickle`, which is known to lead to code execution vulnerabilities. When + unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the + relevant data as JSON or a similar text-based serialization format. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://docs.python.org/3/library/pickle.html + semgrep.dev: + rule: + origin: community + r_id: 9678 + rule_id: 8GUje2 + rv_id: 1263535 + url: https://semgrep.dev/playground/r/NdTzyb4/python.lang.security.deserialization.pickle.avoid-shelve + version_id: NdTzyb4 + shortlink: https://sg.run/dKkZ + source: https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-shelve + subcategory: + - audit + technology: + - python + vulnerability_class: + - 'Insecure Deserialization ' + pattern: shelve.$FUNC(...) + severity: WARNING +- id: python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33633 + rule_id: PeU2e2 + rv_id: 1263536 + url: + https://semgrep.dev/playground/r/kbTzGE1/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + version_id: kbTzGE1 + shortlink: https://sg.run/vYrY + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: hashlib.md5(...) + - pattern-not: hashlib.md5(..., usedforsecurity=False, ...) + severity: WARNING +- fix-regex: + regex: sha1 + replacement: sha256 + id: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + bandit-code: B303 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9624 + rule_id: x8UnBk + rv_id: 1263537 + url: + https://semgrep.dev/playground/r/w8TRoE7/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + version_id: w8TRoE7 + shortlink: https://sg.run/ydYx + source: https://semgrep.dev/r/python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - python + vulnerability_class: + - Cryptographic Issues + pattern: hashlib.sha1(...) + severity: WARNING +- id: python.lang.security.insecure-hash-function.insecure-hash-function + languages: + - python + message: Detected use of an insecure MD4 or MD5 hash function. These functions have known vulnerabilities and are + considered deprecated. Consider using 'SHA256' or a similar function instead. + metadata: + asvs: + control_id: 6.2.2 Insecure Custom Algorithm + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v62-algorithms + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://tools.ietf.org/html/rfc6151 + - https://crypto.stackexchange.com/questions/44151/how-does-the-flame-malware-take-advantage-of-md5-collision + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9625 + rule_id: OrU30g + rv_id: 1501841 + url: https://semgrep.dev/playground/r/xyT0gk7/python.lang.security.insecure-hash-function.insecure-hash-function + version_id: xyT0gk7 + shortlink: https://sg.run/rdBn + source: https://semgrep.dev/r/python.lang.security.insecure-hash-function.insecure-hash-function + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/hashlib_new_insecure_functions.py + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - pattern: hashlib.new("=~/[M|m][D|d][4|5]/", ...) + - pattern: hashlib.new(..., name="=~/[M|m][D|d][4|5]/", ...) + - pattern-not: hashlib.new(..., usedforsecurity=False, ...) + severity: WARNING +- fix-regex: + regex: uuid1 + replacement: uuid4 + id: python.lang.security.insecure-uuid-version.insecure-uuid-version + languages: + - python + message: Using UUID version 1 for UUID generation can lead to predictable UUIDs based on system information (e.g., MAC + address, timestamp). This may lead to security risks such as the sandwich attack. Consider using `uuid.uuid4()` + instead for better randomness and security. + metadata: + asvs: + control_id: 6.3.2 Insecure UUID Generation + control_url: https://github.com/OWASP/ASVS/blob/master/4.0/en/0x14-V6-Cryptography.md#v63-random-values + section: V6 Stored Cryptography Verification Requirements + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-330: Use of Insufficiently Random Values' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.landh.tech/blog/20230811-sandwich-attack/ + semgrep.dev: + rule: + origin: community + r_id: 148295 + rule_id: kxUd1yD + rv_id: 1263539 + url: https://semgrep.dev/playground/r/O9Tpx97/python.lang.security.insecure-uuid-version.insecure-uuid-version + version_id: O9Tpx97 + shortlink: https://sg.run/BYBgW + source: https://semgrep.dev/r/python.lang.security.insecure-uuid-version.insecure-uuid-version + subcategory: + - audit + technology: + - python + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern: uuid.uuid1(...) + severity: WARNING +- fix-regex: + regex: _create_unverified_context + replacement: create_default_context + id: python.lang.security.unverified-ssl-context.unverified-ssl-context + languages: + - python + message: Unverified SSL context detected. This will permit insecure connections without verifying SSL certificates. + Use 'ssl.create_default_context' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://docs.python.org/3/library/ssl.html#ssl-security + - https://docs.python.org/3/library/http.client.html#http.client.HTTPSConnection + semgrep.dev: + rule: + origin: community + r_id: 9627 + rule_id: v8UnkQ + rv_id: 1263540 + url: https://semgrep.dev/playground/r/e1Tyjlj/python.lang.security.unverified-ssl-context.unverified-ssl-context + version_id: e1Tyjlj + shortlink: https://sg.run/N4lp + source: https://semgrep.dev/r/python.lang.security.unverified-ssl-context.unverified-ssl-context + subcategory: + - audit + technology: + - python + vulnerability_class: + - Improper Authentication + patterns: + - pattern-either: + - pattern: ssl._create_unverified_context(...) + - pattern: ssl._create_default_https_context = ssl._create_unverified_context + severity: ERROR +- fix: defusedxml.etree.ElementTree.parse($...ARGS) + id: python.lang.security.use-defused-xml-parse.use-defused-xml-parse + languages: + - python + message: The native Python `xml` library is vulnerable to XML External Entity (XXE) attacks. These attacks can leak + confidential data and "XML bombs" can cause denial of service. Do not use this library to parse untrusted input. + Instead the Python documentation recommends using `defusedxml`. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://docs.python.org/3/library/xml.html + - https://github.com/tiran/defusedxml + - https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing + semgrep.dev: + rule: + origin: community + r_id: 72436 + rule_id: X5Uqnx + rv_id: 1263541 + url: https://semgrep.dev/playground/r/vdT06ER/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + version_id: vdT06ER + shortlink: https://sg.run/n3jG + source: https://semgrep.dev/r/python.lang.security.use-defused-xml-parse.use-defused-xml-parse + subcategory: + - vuln + technology: + - python + vulnerability_class: + - XML Injection + patterns: + - pattern: xml.etree.ElementTree.parse($...ARGS) + - pattern-not: xml.etree.ElementTree.parse("...") + severity: ERROR +- id: python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + languages: + - python + message: Detected Blowfish cipher algorithm which is considered insecure. This algorithm is not cryptographically + secure and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block + cipher such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that + also provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33634 + rule_id: JDUGnK + rv_id: 1263545 + url: + https://semgrep.dev/playground/r/ExTExln/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + version_id: ExTExln + shortlink: https://sg.run/dlOE + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-blowfish.insecure-cipher-algorithm-blowfish + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.Blowfish.new(...) + - pattern: Crypto.Cipher.Blowfish.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + languages: + - python + message: Detected DES cipher or Triple DES algorithm which is considered insecure. This algorithm is not + cryptographically secure and can be reversed easily. Use a secure symmetric cipher from the cryptodome package + instead. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher such as AES with a + block size of 128 bits. When using a block cipher, use a modern mode of operation that also provides authentication, + such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33635 + rule_id: 5rUr73 + rv_id: 1263546 + url: + https://semgrep.dev/playground/r/7ZTE3G7/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + version_id: 7ZTE3G7 + shortlink: https://sg.run/Z5bw + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-des.insecure-cipher-algorithm-des + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.DES.new(...) + - pattern: Crypto.Cipher.DES.new(...) + - pattern: Cryptodome.Cipher.DES3.new(...) + - pattern: Crypto.Cipher.DES3.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + languages: + - python + message: Detected RC2 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher + such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also + provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33636 + rule_id: GdUYlW + rv_id: 1263547 + url: + https://semgrep.dev/playground/r/LjTkgn6/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + version_id: LjTkgn6 + shortlink: https://sg.run/nAbY + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc2.insecure-cipher-algorithm-rc2 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Cryptodome.Cipher.ARC2.new(...) + - pattern: Crypto.Cipher.ARC2.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + languages: + - python + message: Detected ARC4 cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use secure stream ciphers such as ChaCha20, XChaCha20 and Salsa20, or a block cipher + such as AES with a block size of 128 bits. When using a block cipher, use a modern mode of operation that also + provides authentication, such as GCM. + metadata: + bandit-code: B304 + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::symmetric-algorithm::pycryptodome + - crypto::search::symmetric-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://cwe.mitre.org/data/definitions/326.html + - https://www.pycryptodome.org/src/cipher/cipher + semgrep.dev: + rule: + origin: community + r_id: 33637 + rule_id: ReUnEB + rv_id: 1263548 + url: + https://semgrep.dev/playground/r/8KT5rXY/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + version_id: 8KT5rXY + shortlink: https://sg.run/Eo6N + source: + https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm-rc4.insecure-cipher-algorithm-rc4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Cryptodome.Cipher.ARC4.new(...) + - pattern: Crypto.Cipher.ARC4.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + languages: + - python + message: Detected XOR cipher algorithm which is considered insecure. This algorithm is not cryptographically secure + and can be reversed easily. Use AES instead. + metadata: + bandit-code: B304 + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://stackoverflow.com/questions/1135186/whats-wrong-with-xor-encryption + semgrep.dev: + rule: + origin: community + r_id: 9683 + rule_id: PeUk5W + rv_id: 1263549 + url: + https://semgrep.dev/playground/r/gETB7j3/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + version_id: gETB7j3 + shortlink: https://sg.run/L0yr + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-cipher-algorithm.insecure-cipher-algorithm-xor + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L84 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Cryptodome.Cipher.XOR.new(...) + - pattern: Crypto.Cipher.XOR.new(...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + languages: + - python + message: Detected MD2 hash algorithm which is considered insecure. MD2 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33638 + rule_id: AbU0Ex + rv_id: 1263550 + url: + https://semgrep.dev/playground/r/QkTGqD8/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + version_id: QkTGqD8 + shortlink: https://sg.run/7JP2 + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md2.insecure-hash-algorithm-md2 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD2.new(...) + - pattern: Cryptodome.Hash.MD2.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + languages: + - python + message: Detected MD4 hash algorithm which is considered insecure. MD4 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33639 + rule_id: BYUJy4 + rv_id: 1263551 + url: + https://semgrep.dev/playground/r/3ZT4Xnp/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + version_id: 3ZT4Xnp + shortlink: https://sg.run/Lve6 + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md4.insecure-hash-algorithm-md4 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD4.new(...) + - pattern: Cryptodome.Hash.MD4.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + languages: + - python + message: Detected MD5 hash algorithm which is considered insecure. MD5 is not collision resistant and is therefore not + suitable as a cryptographic signature. Use a modern hash algorithm from the SHA-2, SHA-3, or BLAKE2 family instead. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + functional-categories: + - crypto::search::hash-algorithm::pycryptodome + - crypto::search::hash-algorithm::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/hash/hash#modern-hash-algorithms + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 33640 + rule_id: DbUXwo + rv_id: 1263552 + url: + https://semgrep.dev/playground/r/44TEjpk/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + version_id: 44TEjpk + shortlink: https://sg.run/85JN + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm-md5.insecure-hash-algorithm-md5 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + pattern-either: + - pattern: Crypto.Hash.MD5.new(...) + - pattern: Cryptodome.Hash.MD5.new (...) + severity: WARNING +- id: python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + languages: + - python + message: Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore + not suitable as a cryptographic signature. Use SHA256 or SHA3 instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.schneier.com/blog/archives/2012/10/when_will_we_se.html + - https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/sha-1-collision-signals-the-end-of-the-algorithm-s-viability + - http://2012.sharcs.org/slides/stevens.pdf + - https://pycryptodome.readthedocs.io/en/latest/src/hash/sha3_256.html + semgrep.dev: + rule: + origin: community + r_id: 9687 + rule_id: ReUPO3 + rv_id: 1263553 + url: + https://semgrep.dev/playground/r/PkTR3vk/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + version_id: PkTR3vk + shortlink: https://sg.run/3ALr + source: https://semgrep.dev/r/python.pycryptodome.security.insecure-hash-algorithm.insecure-hash-algorithm-sha1 + source-rule-url: + https://github.com/PyCQA/bandit/blob/d5f8fa0d89d7b11442fc6ec80ca42953974354c8/bandit/blacklists/calls.py#L59 + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: Crypto.Hash.SHA.new(...) + - pattern: Cryptodome.Hash.SHA.new (...) + severity: WARNING +- id: python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + languages: + - python + message: Detected an insufficient key size for DSA. NIST recommends a key size of 2048 or higher. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/public_key/dsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + semgrep.dev: + rule: + origin: community + r_id: 9688 + rule_id: AbUWje + rv_id: 1263554 + url: + https://semgrep.dev/playground/r/JdTzxbQ/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + version_id: JdTzxbQ + shortlink: https://sg.run/4y8l + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-dsa-key-size.insufficient-dsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.DSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.DSA.generate($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 2048 + metavariable: $SIZE + severity: WARNING +- id: python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + languages: + - python + message: Detected an insufficient key size for RSA. NIST recommends a key size of 3072 or higher. + metadata: + category: security + confidence: HIGH + cwe: + - 'CWE-326: Inadequate Encryption Strength' + functional-categories: + - crypto::search::key-length::pycryptodome + - crypto::search::key-length::pycryptodomex + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://www.pycryptodome.org/src/public_key/rsa#rsa + - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf + semgrep.dev: + rule: + origin: community + r_id: 9689 + rule_id: BYUBWe + rv_id: 1263555 + url: + https://semgrep.dev/playground/r/5PTo1jL/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + version_id: 5PTo1jL + shortlink: https://sg.run/PprY + source: https://semgrep.dev/r/python.pycryptodome.security.insufficient-rsa-key-size.insufficient-rsa-key-size + source-rule-url: + https://github.com/PyCQA/bandit/blob/b1411bfb43795d3ffd268bef17a839dee954c2b1/bandit/plugins/weak_cryptographic_key.py + subcategory: + - vuln + technology: + - pycryptodome + vulnerability_class: + - Cryptographic Issues + options: + symbolic_propagation: true + patterns: + - pattern-either: + - pattern: Crypto.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Crypto.PublicKey.RSA.generate($SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate(..., bits=$SIZE, ...) + - pattern: Cryptodome.PublicKey.RSA.generate($SIZE, ...) + - metavariable-comparison: + comparison: $SIZE < 3072 + metavariable: $SIZE + severity: WARNING +- id: python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + languages: + - python + message: 'An encryption mode of operation is being used without proper message authentication. This can potentially result + in the encrypted content to be decrypted by an attacker. Consider instead use an AEAD mode of operation like GCM. ' + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 31872 + rule_id: YGUw8w + rv_id: 1263556 + url: + https://semgrep.dev/playground/r/GxTkeyz/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + version_id: GxTkeyz + shortlink: https://sg.run/k1K1 + source: + https://semgrep.dev/r/python.pycryptodome.security.mode-without-authentication.crypto-mode-without-authentication + subcategory: + - vuln + technology: + - cryptography + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-either: + - patterns: + - pattern-either: + - pattern: "AES.new(..., $PYCRYPTODOME_MODE)\n" + - pattern-not-inside: "AES.new(..., $PYCRYPTODOME_MODE)\n...\nHMAC.new\n" + - metavariable-pattern: + metavariable: $PYCRYPTODOME_MODE + patterns: + - pattern-either: + - pattern: AES.MODE_CBC + - pattern: AES.MODE_CTR + - pattern: AES.MODE_CFB + - pattern: AES.MODE_OFB + severity: ERROR +- fix-regex: + regex: MONGODB-CR + replacement: SCRAM-SHA-256 + id: python.pymongo.security.mongodb.mongo-client-bad-auth + languages: + - python + message: Warning MONGODB-CR was deprecated with the release of MongoDB 3.6 and is no longer supported by MongoDB 4.0 + (see https://api.mongodb.com/python/current/examples/authentication.html for details). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-477: Use of Obsolete Function' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://cwe.mitre.org/data/definitions/477.html + semgrep.dev: + rule: + origin: community + r_id: 12658 + rule_id: d8UlOX + rv_id: 946422 + url: https://semgrep.dev/playground/r/0bT15XY/python.pymongo.security.mongodb.mongo-client-bad-auth + version_id: 0bT15XY + shortlink: https://sg.run/YXRd + source: https://semgrep.dev/r/python.pymongo.security.mongodb.mongo-client-bad-auth + subcategory: + - vuln + technology: + - pymongo + vulnerability_class: + - Dangerous Method or Function + pattern: "pymongo.MongoClient(..., authMechanism='MONGODB-CR')\n" + severity: WARNING +- fix: "$...PARAMS, httponly=True\n" + id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies + should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21437 + rule_id: bwUXKB + rv_id: 1263557 + url: + https://semgrep.dev/playground/r/RGT0L7K/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + version_id: RGT0L7K + shortlink: https://sg.run/EprB + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-default.pyramid-authtkt-cookie-httponly-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern: pyramid.authentication.$FUNC($...PARAMS) + - metavariable-pattern: + metavariable: $FUNC + pattern-either: + - pattern: AuthTktCookieHelper + - pattern: AuthTktAuthenticationPolicy + - pattern-not: pyramid.authentication.$FUNC(..., httponly=$HTTPONLY, ...) + - pattern-not: pyramid.authentication.$FUNC(..., **$PARAMS, ...) + - focus-metavariable: $...PARAMS + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the httponly option correctly set. Pyramid cookies + should be handled securely by setting httponly=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21438 + rule_id: NbUq9e + rv_id: 1263558 + url: + https://semgrep.dev/playground/r/A8Tgd8N/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + version_id: A8Tgd8N + shortlink: https://sg.run/7DgQ + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-httponly-unsafe-value.pyramid-authtkt-cookie-httponly-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., httponly=$HTTPONLY, ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., httponly=$HTTPONLY, ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: "False\n" + severity: WARNING +- fix: "'Lax'\n" + id: python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + languages: + - python + message: Found a Pyramid Authentication Ticket without the samesite option correctly set. Pyramid cookies should be + handled securely by setting samesite='Lax'. If this parameter is not properly set, your cookies are not properly + protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21439 + rule_id: kxUYjY + rv_id: 1263559 + url: + https://semgrep.dev/playground/r/BjTkZ51/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + version_id: BjTkZ51 + shortlink: https://sg.run/LYrY + source: https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-samesite.pyramid-authtkt-cookie-samesite + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern: pyramid.authentication.AuthTktCookieHelper(..., samesite=$SAMESITE, ...) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., samesite=$SAMESITE, ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + id: python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + languages: + - python + message: Found a Pyramid Authentication Ticket cookie using an unsafe default for the secure option. Pyramid cookies + should be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21440 + rule_id: wdUKzn + rv_id: 1263560 + url: + https://semgrep.dev/playground/r/DkTRbJn/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + version_id: DkTRbJn + shortlink: https://sg.run/8WxQ + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-default.pyramid-authtkt-cookie-secure-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + languages: + - python + message: Found a Pyramid Authentication Ticket cookie without the secure option correctly set. Pyramid cookies should + be handled securely by setting secure=True. If this parameter is not properly set, your cookies are not properly + protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21441 + rule_id: x8UqAp + rv_id: 1263561 + url: + https://semgrep.dev/playground/r/WrTqK93/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + version_id: WrTqK93 + shortlink: https://sg.run/gjp5 + source: + https://semgrep.dev/r/python.pyramid.audit.authtkt-cookie-secure-unsafe-value.pyramid-authtkt-cookie-secure-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - patterns: + - pattern-not: pyramid.authentication.AuthTktCookieHelper(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktCookieHelper(..., secure=$SECURE, ...) + - patterns: + - pattern-not: pyramid.authentication.AuthTktAuthenticationPolicy(..., **$PARAMS) + - pattern: pyramid.authentication.AuthTktAuthenticationPolicy(..., secure=$SECURE, ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: "False\n" + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + languages: + - python + message: Automatic check of the referrer for cross-site request forgery tokens has been explicitly disabled globally, + which might leave views unprotected when an unsafe CSRF storage policy is used. Use + 'pyramid.config.Configurator.set_default_csrf_options(check_origin=True)' to turn the automatic check for all unsafe + methods (per RFC2616). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21443 + rule_id: eqU9Le + rv_id: 1263563 + url: + https://semgrep.dev/playground/r/K3TKkeo/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + version_id: K3TKkeo + shortlink: https://sg.run/3GeW + source: + https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled-globally.pyramid-csrf-origin-check-disabled-globally + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "$CONFIG.set_default_csrf_options(..., check_origin=$CHECK_ORIGIN, ...)\n" + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + comparison: $CHECK_ORIGIN == False + metavariable: $CHECK_ORIGIN + severity: ERROR +- fix: "True\n" + id: python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + languages: + - python + message: Origin check for the CSRF token is disabled for this view. This might represent a security risk if the CSRF + storage policy is not known to be secure. + metadata: + asvs: + control_id: 4.2.2 CSRF + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + section: V4 Access Control + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21444 + rule_id: v8UGpL + rv_id: 1263564 + url: + https://semgrep.dev/playground/r/qkTR7Gv/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + version_id: qkTR7Gv + shortlink: https://sg.run/4RB9 + source: https://semgrep.dev/r/python.pyramid.audit.csrf-origin-check-disabled.pyramid-csrf-origin-check-disabled + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "from pyramid.view import view_config\n...\n@view_config(..., check_origin=$CHECK_ORIGIN, ...)\ndef $VIEW(...):\n\ + \ ...\n" + - pattern: $CHECK_ORIGIN + - metavariable-comparison: + comparison: $CHECK_ORIGIN == False + metavariable: $CHECK_ORIGIN + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, httponly=True) + id: python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe default for the httponly option. Pyramid cookies should be handled + securely by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies + are not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21445 + rule_id: d8UPQ7 + rv_id: 1263565 + url: + https://semgrep.dev/playground/r/l4TJRbo/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + version_id: l4TJRbo + shortlink: https://sg.run/P19v + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-default.pyramid-set-cookie-httponly-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the httponly option correctly set. Pyramid cookies should be handled securely + by setting httponly=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-1004: Sensitive Cookie Without 'HttpOnly' Flag" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/www-community/controls/SecureCookieAttribute + - https://owasp.org/www-community/HttpOnly + - https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#httponly-attribute + semgrep.dev: + rule: + origin: community + r_id: 21446 + rule_id: ZqU37W + rv_id: 1263566 + url: + https://semgrep.dev/playground/r/YDTZe54/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + version_id: YDTZe54 + shortlink: https://sg.run/JbqP + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-httponly-unsafe-value.pyramid-set-cookie-httponly-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., httponly=$HTTPONLY, ...) + - pattern: $HTTPONLY + - metavariable-pattern: + metavariable: $HTTPONLY + pattern: "False\n" + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, samesite='Lax') + id: python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe value for the samesite option. Pyramid cookies should be handled + securely by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies + are not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21447 + rule_id: nJUp80 + rv_id: 1263567 + url: + https://semgrep.dev/playground/r/6xT293z/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + version_id: 6xT293z + shortlink: https://sg.run/5AWj + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-default.pyramid-set-cookie-samesite-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "'Lax'\n" + id: python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the samesite option correctly set. Pyramid cookies should be handled securely + by setting samesite='Lax' in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-1275: Sensitive Cookie with Improper SameSite Attribute' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21448 + rule_id: EwUgpY + rv_id: 1263568 + url: + https://semgrep.dev/playground/r/o5TbDv5/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + version_id: o5TbDv5 + shortlink: https://sg.run/GXR6 + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-samesite-unsafe-value.pyramid-set-cookie-samesite-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., samesite=$SAMESITE, ...) + - pattern: $SAMESITE + - metavariable-regex: + metavariable: $SAMESITE + regex: (?!'Lax') + severity: WARNING +- fix-regex: + regex: (.*)\) + replacement: \1, secure=True) + id: python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + languages: + - python + message: Found a Pyramid cookie using an unsafe default for the secure option. Pyramid cookies should be handled + securely by setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are + not properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21449 + rule_id: 7KUr15 + rv_id: 1263569 + url: + https://semgrep.dev/playground/r/zyTb2dX/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + version_id: zyTb2dX + shortlink: https://sg.run/RbrN + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-default.pyramid-set-cookie-secure-unsafe-default + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(...) + severity: WARNING +- fix: "True\n" + id: python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + languages: + - python + message: Found a Pyramid cookie without the secure option correctly set. Pyramid cookies should be handled securely by + setting secure=True in response.set_cookie(...). If this parameter is not properly set, your cookies are not + properly protected and are at risk of being stolen by an attacker. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://owasp.org/Top10/A05_2021-Security_Misconfiguration + semgrep.dev: + rule: + origin: community + r_id: 21450 + rule_id: L1UX2J + rv_id: 1263570 + url: + https://semgrep.dev/playground/r/pZT03oJ/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + version_id: pZT03oJ + shortlink: https://sg.run/AzjB + source: + https://semgrep.dev/r/python.pyramid.audit.set-cookie-secure-unsafe-value.pyramid-set-cookie-secure-unsafe-value + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cookie Security + patterns: + - pattern-either: + - pattern-inside: "@pyramid.view.view_config(...)\ndef $VIEW($REQUEST):\n ...\n $RESPONSE = $REQUEST.response\n\ + \ ...\n" + - pattern-inside: "def $VIEW(...):\n ...\n $RESPONSE = pyramid.httpexceptions.HTTPFound(...)\n ...\n" + - pattern-not: $RESPONSE.set_cookie(..., **$PARAMS) + - pattern: $RESPONSE.set_cookie(..., secure=$SECURE, ...) + - pattern: $SECURE + - metavariable-pattern: + metavariable: $SECURE + pattern: "False\n" + severity: WARNING +- fix: "True\n" + id: python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + languages: + - python + message: Automatic check of cross-site request forgery tokens has been explicitly disabled globally, which might leave + views unprotected. Use 'pyramid.config.Configurator.set_default_csrf_options(require_csrf=True)' to turn the + automatic check for all unsafe methods (per RFC2616). + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 21451 + rule_id: 8GUKqP + rv_id: 1263571 + url: + https://semgrep.dev/playground/r/2KTv2en/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + version_id: 2KTv2en + shortlink: https://sg.run/Bx2R + source: + https://semgrep.dev/r/python.pyramid.security.csrf-check-disabled-globally.pyramid-csrf-check-disabled-globally + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "$CONFIG.set_default_csrf_options(..., require_csrf=$REQUIRE_CSRF, ...)\n" + - pattern: $REQUIRE_CSRF + - metavariable-comparison: + comparison: $REQUIRE_CSRF == False + metavariable: $REQUIRE_CSRF + severity: ERROR +- id: python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + languages: + - python + message: Detected data rendered directly to the end user via 'Response'. This bypasses Pyramid's built-in cross-site + scripting (XSS) defenses and could result in an XSS vulnerability. Use Pyramid's template engines to safely render + HTML. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 21452 + rule_id: gxUeA8 + rv_id: 1263572 + url: + https://semgrep.dev/playground/r/X0TzyEe/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + version_id: X0TzyEe + shortlink: https://sg.run/DX8G + source: https://semgrep.dev/r/python.pyramid.security.direct-use-of-response.pyramid-direct-use-of-response + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - Cross-Site-Scripting (XSS) + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "pyramid.request.Response.text($SINK)\n" + - pattern: "pyramid.request.Response($SINK)\n" + - pattern: "$REQ.response.body = $SINK\n" + - pattern: "$REQ.response.text = $SINK\n" + - pattern: "$REQ.response.ubody = $SINK\n" + - pattern: "$REQ.response.unicode_body = $SINK\n" + - pattern: $SINK + pattern-sources: + - patterns: + - pattern-inside: "@pyramid.view.view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- fix-regex: + regex: format + replacement: bindparams + id: python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + languages: + - python + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer + inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs + raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with + any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/tutorial/data_select.html#tutorial-selecting-data + semgrep.dev: + rule: + origin: community + r_id: 21453 + rule_id: QrUZ7l + rv_id: 1263573 + url: + https://semgrep.dev/playground/r/jQTn5WA/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + version_id: jQTn5WA + shortlink: https://sg.run/W7eE + source: https://semgrep.dev/r/python.pyramid.security.sqlalchemy-sql-injection.pyramid-sqlalchemy-sql-injection + subcategory: + - vuln + technology: + - pyramid + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - patterns: + - pattern-inside: "$QUERY = $REQ.dbsession.query(...)\n...\n" + - pattern-either: + - pattern: "$QUERY.$SQLFUNC(\"...\".$FORMATFUNC(..., $SINK, ...))\n" + - pattern: "$QUERY.join(...).$SQLFUNC(\"...\".$FORMATFUNC(..., $SINK, ...))\n" + - pattern: $SINK + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + pattern-sources: + - patterns: + - pattern-inside: "from pyramid.view import view_config\n...\n@view_config( ... )\ndef $VIEW($REQ):\n ...\n" + - pattern: $REQ.$ANYTHING + - pattern-not: $REQ.dbsession + severity: ERROR +- id: python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + languages: + - python + message: sqlalchemy.text passes the constructed SQL statement to the database mostly unchanged. This means that the + usual SQL injection protections are not applied and this function is vulnerable to SQL injection if user input can + reach here. Use normal SQLAlchemy operators (such as `or_()`, `and_()`, etc.) to construct SQL. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://docs.sqlalchemy.org/en/14/core/tutorial.html#using-textual-sql + semgrep.dev: + rule: + origin: community + r_id: 15824 + rule_id: r6U2wE + rv_id: 1263577 + url: + https://semgrep.dev/playground/r/rxTAKqq/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + version_id: rxTAKqq + shortlink: https://sg.run/yP1O + source: https://semgrep.dev/r/python.sqlalchemy.security.audit.avoid-sqlalchemy-text.avoid-sqlalchemy-text + subcategory: + - audit + technology: + - sqlalchemy + vulnerability_class: + - SQL Injection + mode: taint + pattern-sinks: + - pattern: "sqlalchemy.text(...)\n" + pattern-sources: + - patterns: + - pattern: "$X + $Y\n" + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: "$X + $Y\n" + - metavariable-type: + metavariable: $Y + type: string + - patterns: + - pattern: "f\"...\"\n" + - patterns: + - pattern: "$X.format(...)\n" + - metavariable-type: + metavariable: $X + type: string + - patterns: + - pattern: "$X % $Y\n" + - metavariable-type: + metavariable: $X + type: string + severity: ERROR +- fix-regex: + regex: format + replacement: bindparams + id: python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + languages: + - python + message: Distinct, Having, Group_by, Order_by, and Filter in SQLAlchemy can cause sql injections if the developer + inputs raw SQL into the before-mentioned clauses. This pattern captures relevant cases in which the developer inputs + raw SQL into the distinct, having, group_by, order_by or filter clauses and injects user-input into the raw SQL with + any function besides "bindparams". Use bindParams to securely bind user-input to SQL statements. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2017 - Injection + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9702 + rule_id: BYUBWo + rv_id: 1263579 + url: + https://semgrep.dev/playground/r/NdTzyL4/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + version_id: NdTzyL4 + shortlink: https://sg.run/J3Xo + source: https://semgrep.dev/r/python.sqlalchemy.security.sqlalchemy-sql-injection.sqlalchemy-sql-injection + subcategory: + - vuln + technology: + - sqlalchemy + vulnerability_class: + - SQL Injection + patterns: + - pattern-either: + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query(...).$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query.join(...).$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n $SESSION.query.$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - pattern: "def $FUNC(...,$VAR,...):\n ...\n query.$SQLFUNC(\"...\".$FORMATFUNC(...,$VAR,...))\n" + - metavariable-regex: + metavariable: $SQLFUNC + regex: (group_by|order_by|distinct|having|filter) + - metavariable-regex: + metavariable: $FORMATFUNC + regex: (?!bindparams) + severity: WARNING +- id: python.twilio.security.twiml-injection.twiml-injection + languages: + - python + message: Using non-constant TwiML (Twilio Markup Language) argument when creating a Twilio conversation could allow + the injection of additional TwiML commands + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-91: XML Injection' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://codeberg.org/fennix/funjection + semgrep.dev: + rule: + origin: community + r_id: 134692 + rule_id: oqUgjj2 + rv_id: 1263580 + url: https://semgrep.dev/playground/r/kbTzGp1/python.twilio.security.twiml-injection.twiml-injection + version_id: kbTzGp1 + shortlink: https://sg.run/GdEEy + source: https://semgrep.dev/r/python.twilio.security.twiml-injection.twiml-injection + subcategory: + - vuln + technology: + - python + - twilio + - twiml + vulnerability_class: + - Other + mode: taint + pattern-sanitizers: + - pattern: xml.sax.saxutils.escape(...) + - pattern: html.escape(...) + pattern-sinks: + - patterns: + - pattern: "$CLIENT.calls.create(..., twiml=$SINK, ...)\n" + - focus-metavariable: $SINK + pattern-sources: + - pattern: "f\"...\"\n" + - pattern: "\"...\" % ...\n" + - pattern: "\"...\".format(...)\n" + - patterns: + - pattern: $ARG + - pattern-inside: "def $F(..., $ARG, ...):\n ...\n" + severity: WARNING diff --git a/.semgrep/registry/rust-lang-security.yaml b/.semgrep/registry/rust-lang-security.yaml new file mode 100644 index 0000000..ef71446 --- /dev/null +++ b/.semgrep/registry/rust-lang-security.yaml @@ -0,0 +1,347 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): r/rust.lang.security +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: rust.lang.security.args-os.args-os + languages: + - rust + message: 'args_os should not be used for security operations. From the docs: "The first element is traditionally the path + of the executable, but it can be set to arbitrary text, and might not even exist. This means this property should not + be relied upon for security purposes."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.args_os.html + semgrep.dev: + rule: + origin: community + r_id: 40104 + rule_id: DbUeEe + rv_id: 946547 + url: https://semgrep.dev/playground/r/d6TPjBp/rust.lang.security.args-os.args-os + version_id: d6TPjBp + shortlink: https://sg.run/G6k6 + source: https://semgrep.dev/r/rust.lang.security.args-os.args-os + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::args_os() + severity: INFO +- id: rust.lang.security.args.args + languages: + - rust + message: 'args should not be used for security operations. From the docs: "The first element is traditionally the path of + the executable, but it can be set to arbitrary text, and might not even exist. This means this property should not be + relied upon for security purposes."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.args.html + semgrep.dev: + rule: + origin: community + r_id: 40105 + rule_id: WAU6Lk + rv_id: 946548 + url: https://semgrep.dev/playground/r/ZRT35Ly/rust.lang.security.args.args + version_id: ZRT35Ly + shortlink: https://sg.run/RADN + source: https://semgrep.dev/r/rust.lang.security.args.args + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::args() + severity: INFO +- id: rust.lang.security.current-exe.current-exe + languages: + - rust + message: 'current_exe should not be used for security operations. From the docs: "The output of this function should not + be trusted for anything that might have security implications. Basically, if users can run the executable, they can change + the output arbitrarily."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.current_exe.html#security + semgrep.dev: + rule: + origin: community + r_id: 40106 + rule_id: 0oU6nZ + rv_id: 946549 + url: https://semgrep.dev/playground/r/nWTpz6d/rust.lang.security.current-exe.current-exe + version_id: nWTpz6d + shortlink: https://sg.run/AW1B + source: https://semgrep.dev/r/rust.lang.security.current-exe.current-exe + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::current_exe() + severity: INFO +- id: rust.lang.security.insecure-hashes.insecure-hashes + languages: + - rust + message: Detected cryptographically insecure hashing function + metadata: + category: security + confidence: HIGH + cwe: 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://github.com/RustCrypto/hashes + - https://docs.rs/md2/latest/md2/ + - https://docs.rs/md4/latest/md4/ + - https://docs.rs/md5/latest/md5/ + - https://docs.rs/sha-1/latest/sha1/ + semgrep.dev: + rule: + origin: community + r_id: 40107 + rule_id: KxUOxA + rv_id: 946550 + url: https://semgrep.dev/playground/r/ExTg29b/rust.lang.security.insecure-hashes.insecure-hashes + version_id: ExTg29b + shortlink: https://sg.run/B09R + source: https://semgrep.dev/r/rust.lang.security.insecure-hashes.insecure-hashes + subcategory: audit + technology: + - rust + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: md2::Md2::new(...) + - pattern: md4::Md4::new(...) + - pattern: md5::Md5::new(...) + - pattern: sha1::Sha1::new(...) + severity: WARNING +- id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + languages: + - rust + message: Dangerously accepting invalid TLS information + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs + semgrep.dev: + rule: + origin: community + r_id: 40108 + rule_id: qNUKDg + rv_id: 946551 + url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + version_id: 7ZTrQLJ + shortlink: https://sg.run/DqrG + source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + subcategory: vuln + technology: + - reqwest + vulnerability_class: + - Improper Authentication + pattern-either: + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true) + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true) + severity: WARNING +- id: rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + languages: + - rust + message: Set sensitive flag on security headers with 'set_sensitive' to treat data with special care + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-921: Storage of Sensitive Data in a Mechanism without Access Control' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/reqwest/latest/reqwest/header/struct.HeaderValue.html#method.set_sensitive + semgrep.dev: + rule: + origin: community + r_id: 40109 + rule_id: lBUNEw + rv_id: 946552 + url: https://semgrep.dev/playground/r/LjTXy1d/rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + version_id: LjTXy1d + shortlink: https://sg.run/WKlE + source: https://semgrep.dev/r/rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + subcategory: audit + technology: + - reqwest + vulnerability_class: + - Other + patterns: + - pattern: "let mut $HEADERS = header::HeaderMap::new();\n...\nlet $HEADER_VALUE = <... header::HeaderValue::$FROM_FUNC(...) + ...>;\n...\n$HEADERS.insert($HEADER, $HEADER_VALUE);\n" + - pattern-not: "let mut $HEADERS = header::HeaderMap::new();\n...\nlet $HEADER_VALUE = <... header::HeaderValue::$FROM_FUNC(...) + ...>;\n...\n$HEADER_VALUE.set_sensitive(true);\n...\n$HEADERS.insert($HEADER, $HEADER_VALUE);\n" + - metavariable-pattern: + metavariable: $FROM_FUNC + pattern-either: + - pattern: from_static + - pattern: from_str + - pattern: from_name + - pattern: from_bytes + - pattern: from_maybe_shared + - metavariable-pattern: + metavariable: $HEADER + pattern-either: + - pattern: header::AUTHORIZATION + - pattern: '"Authorization"' + severity: INFO +- id: rust.lang.security.rustls-dangerous.rustls-dangerous + languages: + - rust + message: Dangerous client config used, ensure SSL verification + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html + - https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous + semgrep.dev: + rule: + origin: community + r_id: 40110 + rule_id: YGU8LK + rv_id: 946553 + url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous + version_id: 8KTKjdO + shortlink: https://sg.run/01Rw + source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous + subcategory: vuln + technology: + - rustls + vulnerability_class: + - Improper Authentication + pattern-either: + - pattern: rustls::client::DangerousClientConfig + - pattern: $CLIENT.dangerous().set_certificate_verifier(...) + - pattern: "let $CLIENT = rustls::client::ClientConfig::dangerous(...);\n...\n$CLIENT.set_certificate_verifier(...);\n" + severity: WARNING +- id: rust.lang.security.ssl-verify-none.ssl-verify-none + languages: + - rust + message: SSL verification disabled, this allows for MitM attacks + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify + semgrep.dev: + rule: + origin: community + r_id: 40111 + rule_id: 6JU0Bl + rv_id: 946554 + url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none + version_id: gETe1bo + shortlink: https://sg.run/K2Pn + source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none + subcategory: vuln + technology: + - openssl + vulnerability_class: + - Improper Authentication + pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE) + severity: WARNING +- id: rust.lang.security.temp-dir.temp-dir + languages: + - rust + message: "temp_dir should not be used for security operations. From the docs: 'The temporary directory may be shared among + users, or between processes with different privileges; thus, the creation of any files or directories in the temporary + directory must use a secure method to create a uniquely named file. Creating a file or directory with a fixed or predictable + name may result in “insecure temporary file” security vulnerabilities.'" + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.temp_dir.html + semgrep.dev: + rule: + origin: community + r_id: 40112 + rule_id: oqU5AO + rv_id: 946555 + url: https://semgrep.dev/playground/r/QkTZz4Y/rust.lang.security.temp-dir.temp-dir + version_id: QkTZz4Y + shortlink: https://sg.run/qzEO + source: https://semgrep.dev/r/rust.lang.security.temp-dir.temp-dir + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::temp_dir() + severity: INFO +- id: rust.lang.security.unsafe-usage.unsafe-usage + languages: + - rust + message: Detected 'unsafe' usage, please audit for secure usage + metadata: + category: security + confidence: HIGH + cwe: 'CWE-242: Use of Inherently Dangerous Function' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/std/keyword.unsafe.html + semgrep.dev: + rule: + origin: community + r_id: 40113 + rule_id: zdUezd + rv_id: 946556 + url: https://semgrep.dev/playground/r/3ZTOPoZ/rust.lang.security.unsafe-usage.unsafe-usage + version_id: 3ZTOPoZ + shortlink: https://sg.run/lqgo + source: https://semgrep.dev/r/rust.lang.security.unsafe-usage.unsafe-usage + subcategory: audit + technology: + - rust + vulnerability_class: + - Dangerous Method or Function + pattern: unsafe { ... } + severity: INFO diff --git a/.semgrep/registry/rust.yaml b/.semgrep/registry/rust.yaml new file mode 100644 index 0000000..6fe105b --- /dev/null +++ b/.semgrep/registry/rust.yaml @@ -0,0 +1,413 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/rust +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: generic.unicode.security.bidi.contains-bidirectional-characters + languages: + - bash + - c + - csharp + - go + - java + - javascript + - json + - kotlin + - lua + - ocaml + - php + - python + - ruby + - rust + - scala + - sh + - typescript + - yaml + message: This code contains bidirectional (bidi) characters. While this is useful for support of right-to-left + languages such as Arabic or Hebrew, it can also be used to trick language parsers into executing code in a manner + that is different from how it is displayed in code editing and review tools. If this is not what you were expecting, + please review this code in an editor that can reveal hidden Unicode characters. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://trojansource.codes/ + semgrep.dev: + rule: + origin: community + r_id: 14880 + rule_id: d8UeX4 + rv_id: 1262904 + url: https://semgrep.dev/playground/r/JdTzxzn/generic.unicode.security.bidi.contains-bidirectional-characters + version_id: JdTzxzn + shortlink: https://sg.run/nK4r + source: https://semgrep.dev/r/generic.unicode.security.bidi.contains-bidirectional-characters + subcategory: + - audit + technology: + - unicode + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - pattern-regex: ‪ + - pattern-regex: ‫ + - pattern-regex: ‭ + - pattern-regex: ‮ + - pattern-regex: ⁦ + - pattern-regex: ⁧ + - pattern-regex: ⁨ + - pattern-regex: ‬ + - pattern-regex: ⁩ + severity: WARNING +- id: rust.lang.security.args-os.args-os + languages: + - rust + message: 'args_os should not be used for security operations. From the docs: "The first element is traditionally the path + of the executable, but it can be set to arbitrary text, and might not even exist. This means this property should not + be relied upon for security purposes."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.args_os.html + semgrep.dev: + rule: + origin: community + r_id: 40104 + rule_id: DbUeEe + rv_id: 946547 + url: https://semgrep.dev/playground/r/d6TPjBp/rust.lang.security.args-os.args-os + version_id: d6TPjBp + shortlink: https://sg.run/G6k6 + source: https://semgrep.dev/r/rust.lang.security.args-os.args-os + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::args_os() + severity: INFO +- id: rust.lang.security.args.args + languages: + - rust + message: 'args should not be used for security operations. From the docs: "The first element is traditionally the path of + the executable, but it can be set to arbitrary text, and might not even exist. This means this property should not be + relied upon for security purposes."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.args.html + semgrep.dev: + rule: + origin: community + r_id: 40105 + rule_id: WAU6Lk + rv_id: 946548 + url: https://semgrep.dev/playground/r/ZRT35Ly/rust.lang.security.args.args + version_id: ZRT35Ly + shortlink: https://sg.run/RADN + source: https://semgrep.dev/r/rust.lang.security.args.args + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::args() + severity: INFO +- id: rust.lang.security.current-exe.current-exe + languages: + - rust + message: 'current_exe should not be used for security operations. From the docs: "The output of this function should not + be trusted for anything that might have security implications. Basically, if users can run the executable, they can change + the output arbitrarily."' + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.current_exe.html#security + semgrep.dev: + rule: + origin: community + r_id: 40106 + rule_id: 0oU6nZ + rv_id: 946549 + url: https://semgrep.dev/playground/r/nWTpz6d/rust.lang.security.current-exe.current-exe + version_id: nWTpz6d + shortlink: https://sg.run/AW1B + source: https://semgrep.dev/r/rust.lang.security.current-exe.current-exe + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::current_exe() + severity: INFO +- id: rust.lang.security.insecure-hashes.insecure-hashes + languages: + - rust + message: Detected cryptographically insecure hashing function + metadata: + category: security + confidence: HIGH + cwe: 'CWE-328: Use of Weak Hash' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://github.com/RustCrypto/hashes + - https://docs.rs/md2/latest/md2/ + - https://docs.rs/md4/latest/md4/ + - https://docs.rs/md5/latest/md5/ + - https://docs.rs/sha-1/latest/sha1/ + semgrep.dev: + rule: + origin: community + r_id: 40107 + rule_id: KxUOxA + rv_id: 946550 + url: https://semgrep.dev/playground/r/ExTg29b/rust.lang.security.insecure-hashes.insecure-hashes + version_id: ExTg29b + shortlink: https://sg.run/B09R + source: https://semgrep.dev/r/rust.lang.security.insecure-hashes.insecure-hashes + subcategory: audit + technology: + - rust + vulnerability_class: + - Insecure Hashing Algorithm + pattern-either: + - pattern: md2::Md2::new(...) + - pattern: md4::Md4::new(...) + - pattern: md5::Md5::new(...) + - pattern: sha1::Sha1::new(...) + severity: WARNING +- id: rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + languages: + - rust + message: Dangerously accepting invalid TLS information + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_hostnames + - https://docs.rs/reqwest/latest/reqwest/struct.ClientBuilder.html#method.danger_accept_invalid_certs + semgrep.dev: + rule: + origin: community + r_id: 40108 + rule_id: qNUKDg + rv_id: 946551 + url: https://semgrep.dev/playground/r/7ZTrQLJ/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + version_id: 7ZTrQLJ + shortlink: https://sg.run/DqrG + source: https://semgrep.dev/r/rust.lang.security.reqwest-accept-invalid.reqwest-accept-invalid + subcategory: vuln + technology: + - reqwest + vulnerability_class: + - Improper Authentication + pattern-either: + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_hostnames(true) + - pattern: reqwest::Client::builder(). ... .danger_accept_invalid_certs(true) + severity: WARNING +- id: rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + languages: + - rust + message: Set sensitive flag on security headers with 'set_sensitive' to treat data with special care + metadata: + category: security + confidence: MEDIUM + cwe: 'CWE-921: Storage of Sensitive Data in a Mechanism without Access Control' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/reqwest/latest/reqwest/header/struct.HeaderValue.html#method.set_sensitive + semgrep.dev: + rule: + origin: community + r_id: 40109 + rule_id: lBUNEw + rv_id: 946552 + url: https://semgrep.dev/playground/r/LjTXy1d/rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + version_id: LjTXy1d + shortlink: https://sg.run/WKlE + source: https://semgrep.dev/r/rust.lang.security.reqwest-set-sensitive.reqwest-set-sensitive + subcategory: audit + technology: + - reqwest + vulnerability_class: + - Other + patterns: + - pattern: "let mut $HEADERS = header::HeaderMap::new();\n...\nlet $HEADER_VALUE = <... header::HeaderValue::$FROM_FUNC(...) + ...>;\n...\n$HEADERS.insert($HEADER, $HEADER_VALUE);\n" + - pattern-not: "let mut $HEADERS = header::HeaderMap::new();\n...\nlet $HEADER_VALUE = <... header::HeaderValue::$FROM_FUNC(...) + ...>;\n...\n$HEADER_VALUE.set_sensitive(true);\n...\n$HEADERS.insert($HEADER, $HEADER_VALUE);\n" + - metavariable-pattern: + metavariable: $FROM_FUNC + pattern-either: + - pattern: from_static + - pattern: from_str + - pattern: from_name + - pattern: from_bytes + - pattern: from_maybe_shared + - metavariable-pattern: + metavariable: $HEADER + pattern-either: + - pattern: header::AUTHORIZATION + - pattern: '"Authorization"' + severity: INFO +- id: rust.lang.security.rustls-dangerous.rustls-dangerous + languages: + - rust + message: Dangerous client config used, ensure SSL verification + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/rustls/latest/rustls/client/struct.DangerousClientConfig.html + - https://docs.rs/rustls/latest/rustls/client/struct.ClientConfig.html#method.dangerous + semgrep.dev: + rule: + origin: community + r_id: 40110 + rule_id: YGU8LK + rv_id: 946553 + url: https://semgrep.dev/playground/r/8KTKjdO/rust.lang.security.rustls-dangerous.rustls-dangerous + version_id: 8KTKjdO + shortlink: https://sg.run/01Rw + source: https://semgrep.dev/r/rust.lang.security.rustls-dangerous.rustls-dangerous + subcategory: vuln + technology: + - rustls + vulnerability_class: + - Improper Authentication + pattern-either: + - pattern: rustls::client::DangerousClientConfig + - pattern: $CLIENT.dangerous().set_certificate_verifier(...) + - pattern: "let $CLIENT = rustls::client::ClientConfig::dangerous(...);\n...\n$CLIENT.set_certificate_verifier(...);\n" + severity: WARNING +- id: rust.lang.security.ssl-verify-none.ssl-verify-none + languages: + - rust + message: SSL verification disabled, this allows for MitM attacks + metadata: + category: security + confidence: HIGH + cwe: 'CWE-295: Improper Certificate Validation' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://docs.rs/openssl/latest/openssl/ssl/struct.SslContextBuilder.html#method.set_verify + semgrep.dev: + rule: + origin: community + r_id: 40111 + rule_id: 6JU0Bl + rv_id: 946554 + url: https://semgrep.dev/playground/r/gETe1bo/rust.lang.security.ssl-verify-none.ssl-verify-none + version_id: gETe1bo + shortlink: https://sg.run/K2Pn + source: https://semgrep.dev/r/rust.lang.security.ssl-verify-none.ssl-verify-none + subcategory: vuln + technology: + - openssl + vulnerability_class: + - Improper Authentication + pattern: $BUILDER.set_verify(openssl::ssl::SSL_VERIFY_NONE) + severity: WARNING +- id: rust.lang.security.temp-dir.temp-dir + languages: + - rust + message: "temp_dir should not be used for security operations. From the docs: 'The temporary directory may be shared among + users, or between processes with different privileges; thus, the creation of any files or directories in the temporary + directory must use a secure method to create a uniquely named file. Creating a file or directory with a fixed or predictable + name may result in “insecure temporary file” security vulnerabilities.'" + metadata: + category: security + confidence: HIGH + cwe: 'CWE-807: Reliance on Untrusted Inputs in a Security Decision' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/stable/std/env/fn.temp_dir.html + semgrep.dev: + rule: + origin: community + r_id: 40112 + rule_id: oqU5AO + rv_id: 946555 + url: https://semgrep.dev/playground/r/QkTZz4Y/rust.lang.security.temp-dir.temp-dir + version_id: QkTZz4Y + shortlink: https://sg.run/qzEO + source: https://semgrep.dev/r/rust.lang.security.temp-dir.temp-dir + subcategory: audit + technology: + - rust + vulnerability_class: + - Other + pattern: std::env::temp_dir() + severity: INFO +- id: rust.lang.security.unsafe-usage.unsafe-usage + languages: + - rust + message: Detected 'unsafe' usage, please audit for secure usage + metadata: + category: security + confidence: HIGH + cwe: 'CWE-242: Use of Inherently Dangerous Function' + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://doc.rust-lang.org/std/keyword.unsafe.html + semgrep.dev: + rule: + origin: community + r_id: 40113 + rule_id: zdUezd + rv_id: 946556 + url: https://semgrep.dev/playground/r/3ZTOPoZ/rust.lang.security.unsafe-usage.unsafe-usage + version_id: 3ZTOPoZ + shortlink: https://sg.run/lqgo + source: https://semgrep.dev/r/rust.lang.security.unsafe-usage.unsafe-usage + subcategory: audit + technology: + - rust + vulnerability_class: + - Dangerous Method or Function + pattern: unsafe { ... } + severity: INFO diff --git a/.semgrep/registry/security-audit.yaml b/.semgrep/registry/security-audit.yaml new file mode 100644 index 0000000..c16fcc0 --- /dev/null +++ b/.semgrep/registry/security-audit.yaml @@ -0,0 +1,11225 @@ +# GENERATED FILE - DO NOT EDIT. +# Snapshot of Semgrep registry config(s): p/security-audit +# Rules are fetched from https://semgrep.dev/c/, deduplicated by rule id, +# and sorted. Refresh with: python3 .github/scripts/semgrep_registry.py sync +# (the semgrep-registry-update workflow does this on a schedule). +rules: +- id: c.lang.security.double-free.double-free + languages: + - c + message: Variable '$VAR' was freed twice. This can lead to undefined behavior. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-415: Double Free' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A01:2017 - Injection + - A05:2025 - Injection + references: + - https://cwe.mitre.org/data/definitions/415.html + - https://owasp.org/www-community/vulnerabilities/Doubly_freeing_memory + semgrep.dev: + rule: + origin: community + r_id: 8832 + rule_id: JDUyw8 + rv_id: 1262604 + url: https://semgrep.dev/playground/r/RGT0L3W/c.lang.security.double-free.double-free + version_id: RGT0L3W + shortlink: https://sg.run/eLl0 + source: https://semgrep.dev/r/c.lang.security.double-free.double-free + subcategory: + - vuln + technology: + - c + vulnerability_class: + - Memory Issues + patterns: + - pattern-not: "free($VAR);\n...\n$VAR = NULL;\n...\nfree($VAR);\n" + - pattern-not: "free($VAR);\n...\n$VAR = malloc(...);\n...\nfree($VAR);\n" + - pattern-inside: "free($VAR);\n...\n$FREE($VAR);\n" + - metavariable-pattern: + metavariable: $FREE + pattern: free + - focus-metavariable: $FREE + severity: ERROR +- id: c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + languages: + - c + message: Avoid 'gets()'. This function does not consider buffer boundaries and can lead to buffer overflows. Use + 'fgets()' or 'gets_s()' instead. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://us-cert.cisa.gov/bsi/articles/knowledge/coding-practices/fgets-and-gets_s + semgrep.dev: + rule: + origin: community + r_id: 8834 + rule_id: GdU7OE + rv_id: 945170 + url: https://semgrep.dev/playground/r/YDTvRlQ/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + version_id: YDTvRlQ + shortlink: https://sg.run/dKqX + source: https://semgrep.dev/r/c.lang.security.insecure-use-gets-fn.insecure-use-gets-fn + subcategory: + - audit + technology: + - c + vulnerability_class: + - Dangerous Method or Function + pattern: gets(...) + severity: ERROR +- id: c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + languages: + - c + message: Avoid using user-controlled format strings passed into 'sprintf', 'printf' and 'vsprintf'. These functions + put you at risk of buffer overflow vulnerabilities through the use of format string exploits. Instead, use + 'snprintf' and 'vsnprintf'. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-134: Use of Externally-Controlled Format String' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + references: + - https://doc.castsoftware.com/display/SBX/Never+use+sprintf%28%29+or+vsprintf%28%29+functions + - https://www.cvedetails.com/cwe-details/134/Uncontrolled-Format-String.html + semgrep.dev: + rule: + origin: community + r_id: 8835 + rule_id: ReUgWx + rv_id: 945172 + url: https://semgrep.dev/playground/r/o5TZeB2/c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + version_id: o5TZeB2 + shortlink: https://sg.run/ZvJx + source: https://semgrep.dev/r/c.lang.security.insecure-use-printf-fn.insecure-use-printf-fn + subcategory: + - vuln + technology: + - c + vulnerability_class: + - Improper Validation + patterns: + - pattern-either: + - pattern: "$FUNC($BUFFER, argv[$NUM], ...);\n...\nvsprintf(..., $BUFFER, ...);\n" + - pattern: vsprintf(..., argv[$NUM], ...) + - pattern: "$FUNC($BUFFER, argv[$NUM], ...);\n...\nsprintf(..., $BUFFER, ...);\n" + - pattern: sprintf(...,argv[$NUM],...) + - pattern: "$FUNC($BUFFER, argv[$NUM], ...);\n...\nprintf(..., $BUFFER, ...);\n" + - pattern: printf(...,argv[$NUM],...) + - metavariable-comparison: + comparison: int($NUM) > 0 + metavariable: $NUM + severity: WARNING +- id: c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + languages: + - c + message: Avoid using 'scanf()'. This function, when used improperly, does not consider buffer boundaries and can lead + to buffer overflows. Use 'fgets()' instead for reading input. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - http://sekrit.de/webdocs/c/beginners-guide-away-from-scanf.html + semgrep.dev: + rule: + origin: community + r_id: 8836 + rule_id: AbUzPd + rv_id: 945173 + url: https://semgrep.dev/playground/r/zyTlkWW/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + version_id: zyTlkWW + shortlink: https://sg.run/nd1g + source: https://semgrep.dev/r/c.lang.security.insecure-use-scanf-fn.insecure-use-scanf-fn + subcategory: + - audit + technology: + - c + vulnerability_class: + - Dangerous Method or Function + pattern: scanf(...) + severity: WARNING +- id: c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + languages: + - c + message: Finding triggers whenever there is a strcat or strncat used. This is an issue because strcat or strncat can + lead to buffer overflow vulns. Fix this by using strcat_s instead. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://nvd.nist.gov/vuln/detail/CVE-2019-12553 + - https://techblog.mediaservice.net/2020/04/cve-2020-2851-stack-based-buffer-overflow-in-cde-libdtsvc/ + semgrep.dev: + rule: + origin: community + r_id: 8837 + rule_id: BYUNjA + rv_id: 945174 + url: https://semgrep.dev/playground/r/pZTNOXb/c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + version_id: pZTNOXb + shortlink: https://sg.run/EkRP + source: https://semgrep.dev/r/c.lang.security.insecure-use-strcat-fn.insecure-use-strcat-fn + subcategory: + - audit + technology: + - c + vulnerability_class: + - Dangerous Method or Function + pattern-either: + - pattern: strcat(...) + - pattern: strncat(...) + severity: WARNING +- id: c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn + languages: + - c + message: Finding triggers whenever there is a strcpy or strncpy used. This is an issue because strcpy does not affirm + the size of the destination array and strncpy will not automatically NULL-terminate strings. This can lead to buffer + overflows, which can cause program crashes and potentially let an attacker inject code in the program. Fix this by + using strcpy_s instead (although note that strcpy_s is an optional part of the C11 standard, and so may not be + available). + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://cwe.mitre.org/data/definitions/676 + - https://nvd.nist.gov/vuln/detail/CVE-2019-11365 + semgrep.dev: + rule: + origin: community + r_id: 8838 + rule_id: DbUpo5 + rv_id: 945175 + url: + https://semgrep.dev/playground/r/2KTYb7Y/c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn + version_id: 2KTYb7Y + shortlink: https://sg.run/7oNk + source: https://semgrep.dev/r/c.lang.security.insecure-use-string-copy-fn.insecure-use-string-copy-fn + subcategory: + - audit + technology: + - c + vulnerability_class: + - Dangerous Method or Function + pattern-either: + - pattern: strcpy(...) + - pattern: strncpy(...) + severity: WARNING +- id: c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + languages: + - c + message: Avoid using 'strtok()'. This function directly modifies the first argument buffer, permanently erasing the + delimiter character. Use 'strtok_r()' instead. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-676: Use of Potentially Dangerous Function' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://wiki.sei.cmu.edu/confluence/display/c/STR06-C.+Do+not+assume+that+strtok%28%29+leaves+the+parse+string+unchanged + - https://man7.org/linux/man-pages/man3/strtok.3.html#BUGS + - https://stackoverflow.com/a/40335556 + semgrep.dev: + rule: + origin: community + r_id: 8839 + rule_id: WAUo5v + rv_id: 1028278 + url: https://semgrep.dev/playground/r/qkTx1oq/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + version_id: qkTx1oq + shortlink: https://sg.run/LwqG + source: https://semgrep.dev/r/c.lang.security.insecure-use-strtok-fn.insecure-use-strtok-fn + subcategory: + - audit + technology: + - c + vulnerability_class: + - Dangerous Method or Function + pattern: strtok(...) + severity: WARNING +- id: c.lang.security.random-fd-exhaustion.random-fd-exhaustion + languages: + - c + message: Call to 'read()' without error checking is susceptible to file descriptor exhaustion. Consider using the + 'getrandom()' function. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-774: Allocation of File Descriptors or Handles Without Limits or Throttling' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://lwn.net/Articles/606141/ + semgrep.dev: + rule: + origin: community + r_id: 8840 + rule_id: 0oU5k4 + rv_id: 945177 + url: https://semgrep.dev/playground/r/jQTzvry/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + version_id: jQTzvry + shortlink: https://sg.run/8yNj + source: https://semgrep.dev/r/c.lang.security.random-fd-exhaustion.random-fd-exhaustion + subcategory: + - audit + technology: + - c + vulnerability_class: + - Denial-of-Service (DoS) + pattern-either: + - patterns: + - pattern: "$FD = open(\"/dev/urandom\", ...);\n...\nread($FD, ...);\n" + - pattern-not: "$FD = open(\"/dev/urandom\", ...);\n...\n$BYTES_READ = read($FD, ...);\n" + - patterns: + - pattern: "$FD = open(\"/dev/random\", ...);\n...\nread($FD, ...);\n" + - pattern-not: "$FD = open(\"/dev/random\", ...);\n...\n$BYTES_READ = read($FD, ...);\n" + severity: WARNING +- id: c.lang.security.use-after-free.use-after-free + languages: + - c + message: Variable '$VAR' was used after being freed. This can lead to undefined behavior. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-416: Use After Free' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + references: + - https://cwe.mitre.org/data/definitions/416.html + - https://ctf-wiki.github.io/ctf-wiki/pwn/linux/glibc-heap/use_after_free/ + semgrep.dev: + rule: + origin: community + r_id: 8841 + rule_id: KxUb9l + rv_id: 945178 + url: https://semgrep.dev/playground/r/1QToKPy/c.lang.security.use-after-free.use-after-free + version_id: 1QToKPy + shortlink: https://sg.run/gL6e + source: https://semgrep.dev/r/c.lang.security.use-after-free.use-after-free + subcategory: + - vuln + technology: + - c + vulnerability_class: + - Memory Issues + patterns: + - pattern-either: + - pattern: $VAR->$ACCESSOR + - pattern: (*$VAR).$ACCESSOR + - pattern: $VAR[$NUM] + - pattern-inside: free($VAR); ... + - pattern-not-inside: $VAR = NULL; ... + - pattern-not-inside: free($VAR); ... $VAR = malloc(...); ... + severity: WARNING +- id: dockerfile.security.last-user-is-root.last-user-is-root + languages: + - dockerfile + message: The last user in the container is 'root'. This is a security hazard because if an attacker gains control of + the container they will have root access. Switch back to another user after running commands as 'root'. + metadata: + category: security + confidence: MEDIUM + cwe: + - 'CWE-269: Improper Privilege Management' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A04:2021 - Insecure Design + - A06:2025 - Insecure Design + references: + - https://github.com/hadolint/hadolint/wiki/DL3002 + semgrep.dev: + rule: + origin: community + r_id: 20147 + rule_id: ReU2n5 + rv_id: 1262658 + url: https://semgrep.dev/playground/r/6xT29Eg/dockerfile.security.last-user-is-root.last-user-is-root + version_id: 6xT29Eg + shortlink: https://sg.run/5Z43 + source: https://semgrep.dev/r/dockerfile.security.last-user-is-root.last-user-is-root + source-rule-url: https://github.com/hadolint/hadolint/wiki/DL3002 + subcategory: + - audit + technology: + - dockerfile + vulnerability_class: + - Improper Authorization + patterns: + - pattern: USER root + - pattern-not-inside: + patterns: + - pattern: "USER root\n...\nUSER $X\n" + - metavariable-pattern: + metavariable: $X + patterns: + - pattern-not: root + severity: ERROR +- fix-regex: + regex: '{{(.*?)}}' + replacement: '"{{\1}}"' + id: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var + languages: + - generic + message: 'Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript + handlers. To fix this, add quotes around the template expression, like this: "{{ expr }}".' + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/1.1.x/security/#cross-site-scripting-xss + semgrep.dev: + rule: + origin: community + r_id: 9029 + rule_id: gxU1jy + rv_id: 1501833 + url: + https://semgrep.dev/playground/r/1QT3R1A/generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var + version_id: 1QT3R1A + shortlink: https://sg.run/weNX + source: https://semgrep.dev/r/generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var + subcategory: + - audit + technology: + - html-templates + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.html' + - '*.mustache' + - '*.hbs' + - '*.twig' + patterns: + - pattern-inside: <$TAG ...> + - pattern-not-inside: ="..." + - pattern-not-inside: ="{{ ... }}" + - pattern-not-inside: ='...' + - pattern-not-inside: ='{{ ... }}' + - pattern: '{{ ... }}' + severity: WARNING +- id: generic.html-templates.security.var-in-href.var-in-href + languages: + - generic + message: Detected a template variable used in an anchor tag with the 'href' attribute. This allows a malicious actor + to input the 'javascript:' URI and is subject to cross- site scripting (XSS) attacks. If using Flask, use + 'url_for()' to safely generate a URL. If using Django, use the 'url' filter to safely generate a URL. If using + Mustache, use a URL encoding library, or prepend a slash '/' to the variable for relative links + (`href="/{{link}}"`). You may also consider setting the Content Security Policy (CSP) header. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://flask.palletsprojects.com/en/1.1.x/security/#cross-site-scripting-xss#:~:text=javascript:%20URI + - https://docs.djangoproject.com/en/3.1/ref/templates/builtins/#url + - https://github.com/pugjs/pug/issues/2952 + - https://content-security-policy.com/ + semgrep.dev: + rule: + origin: community + r_id: 9030 + rule_id: QrUzD1 + rv_id: 1501834 + url: https://semgrep.dev/playground/r/9lTqGx9/generic.html-templates.security.var-in-href.var-in-href + version_id: 9lTqGx9 + shortlink: https://sg.run/x1kP + source: https://semgrep.dev/r/generic.html-templates.security.var-in-href.var-in-href + subcategory: + - audit + technology: + - html-templates + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.html' + - '*.mustache' + - '*.hbs' + - '*.twig' + patterns: + - pattern-inside: + - pattern-either: + - pattern: href = {{ ... }} + - pattern: href = "{{ ... }}" + - pattern: href = '{{ ... }}' + - pattern-not-inside: href = {{ url_for(...) ... }} + - pattern-not-inside: href = "{{ url_for(...) ... }}" + - pattern-not-inside: href = '{{ url_for(...) ... }}' + - pattern-not-inside: href = "/{{ ... }}" + - pattern-not-inside: href = '/{{ ... }}' + severity: WARNING +- id: generic.html-templates.security.var-in-script-tag.var-in-script-tag + languages: + - generic + message: Detected a template variable used in a script tag. Although template variables are HTML escaped, HTML + escaping does not always prevent cross-site scripting (XSS) attacks when used directly in JavaScript. If you need + this data on the rendered page, consider placing it in the HTML portion (outside of a script tag). Alternatively, + use a JavaScript-specific encoder, such as the one available in OWASP ESAPI. For Django, you may also consider using + the 'json_script' template tag and retrieving the data in your script by using the element ID (e.g., + `document.getElementById`). + metadata: + category: security + confidence: LOW + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://adamj.eu/tech/2020/02/18/safely-including-data-for-javascript-in-a-django-template/?utm_campaign=Django%2BNewsletter&utm_medium=rss&utm_source=Django_Newsletter_12A + - https://www.veracode.com/blog/secure-development/nodejs-template-engines-why-default-encoders-are-not-enough + - https://github.com/ESAPI/owasp-esapi-js + semgrep.dev: + rule: + origin: community + r_id: 9032 + rule_id: 4bUkpl + rv_id: 1501836 + url: + https://semgrep.dev/playground/r/rxTlpQE/generic.html-templates.security.var-in-script-tag.var-in-script-tag + version_id: rxTlpQE + shortlink: https://sg.run/eLWE + source: https://semgrep.dev/r/generic.html-templates.security.var-in-script-tag.var-in-script-tag + subcategory: + - audit + technology: + - html-templates + vulnerability_class: + - Cross-Site-Scripting (XSS) + paths: + include: + - '*.mustache' + - '*.hbs' + - '*.html' + - '*.twig' + patterns: + - pattern-inside: + - pattern-not-inside: \", $X.CASE_INSENSITIVE);\n$V = $P.matcher(...).replaceAll(\"\");" + severity: WARNING +- id: java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + languages: + - java + message: Detected a potential path traversal. A malicious actor could control the location of this file, to include + going backwards in the directory with '../'. To address this, ensure that user-controlled variables in file paths + are sanitized. You may also consider using a utility method such as org.apache.commons.io.FilenameUtils.getName(...) + to only retrieve the file name from the path. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A05:2017 - Broken Access Control + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://www.owasp.org/index.php/Path_Traversal + semgrep.dev: + rule: + origin: community + r_id: 9160 + rule_id: NbUk7X + rv_id: 1263064 + url: + https://semgrep.dev/playground/r/zyTb2rq/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + version_id: zyTb2rq + shortlink: https://sg.run/oxXN + source: https://semgrep.dev/r/java.lang.security.httpservlet-path-traversal.httpservlet-path-traversal + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#PATH_TRAVERSAL_IN + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Path Traversal + mode: taint + pattern-sanitizers: + - pattern: org.apache.commons.io.FilenameUtils.getName(...) + pattern-sinks: + - patterns: + - pattern-either: + - pattern: "(java.io.File $FILE) = ...\n" + - pattern: "(java.io.FileOutputStream $FOS) = ...\n" + - pattern: "new java.io.FileInputStream(...)\n" + pattern-sources: + - patterns: + - pattern-either: + - pattern: "(HttpServletRequest $REQ)\n" + - patterns: + - pattern-inside: "(javax.servlet.http.Cookie[] $COOKIES) = (HttpServletRequest $REQ).getCookies(...);\n...\nfor (javax.servlet.http.Cookie + $COOKIE: $COOKIES) {\n ...\n}\n" + - pattern: "$COOKIE.getValue(...)\n" + - patterns: + - pattern-inside: "$TYPE[] $VALS = (HttpServletRequest $REQ).$GETFUNC(...);\n...\n" + - pattern: "$PARAM = $VALS[$INDEX];\n" + severity: ERROR +- id: java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + languages: + - java + message: "Cross-site scripting detected in HttpServletResponse writer with variable '$VAR'. User input was detected going + directly from the HttpServletRequest into output. Ensure your data is properly encoded using org.owasp.encoder.Encode.forHtml: + 'Encode.forHtml($VAR)'." + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A07:2017 - Cross-Site Scripting (XSS) + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9162 + rule_id: wdUJOk + rv_id: 1263066 + url: + https://semgrep.dev/playground/r/2KTv2EG/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + version_id: 2KTv2EG + shortlink: https://sg.run/pxjN + source: https://semgrep.dev/r/java.lang.security.servletresponse-writer-xss.servletresponse-writer-xss + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#XSS_SERVLET + subcategory: + - vuln + technology: + - java + vulnerability_class: + - Cross-Site-Scripting (XSS) + patterns: + - pattern-inside: $TYPE $FUNC(..., HttpServletResponse $RESP, ...) { ... } + - pattern-inside: $VAR = $REQ.getParameter(...); ... + - pattern-either: + - pattern: $RESP.getWriter(...).write(..., $VAR, ...); + - pattern: "$WRITER = $RESP.getWriter(...);\n...\n$WRITER.write(..., $VAR, ...);\n" + severity: ERROR +- id: java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + languages: + - java + message: XML external entities are enabled for this XMLInputFactory. This is vulnerable to XML external entity + attacks. Disable external entities by setting "javax.xml.stream.isSupportingExternalEntities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: LOW + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + semgrep.dev: + rule: + origin: community + r_id: 9163 + rule_id: x8Unkq + rv_id: 1263068 + url: + https://semgrep.dev/playground/r/jQTn5Jv/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + version_id: jQTn5Jv + shortlink: https://sg.run/2x75 + source: + https://semgrep.dev/r/java.lang.security.xmlinputfactory-external-entities-enabled.xmlinputfactory-external-entities-enabled + subcategory: + - audit + technology: + - java + vulnerability_class: + - XML Injection + patterns: + - pattern-either: + - pattern: (javax.xml.stream.XMLInputFactory + $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", true); + - pattern: (javax.xml.stream.XMLInputFactory + $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, true); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + true); + - pattern: (javax.xml.stream.XMLInputFactory + $XMLFACTORY).setProperty("javax.xml.stream.isSupportingExternalEntities", Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory + $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, Boolean.TRUE); + - pattern: (javax.xml.stream.XMLInputFactory $XMLFACTORY).setProperty(javax.xml.stream.XMLInputFactory.SUPPORT_DTD, + Boolean.TRUE); + severity: ERROR +- id: java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + languages: + - java + message: XML external entities are not explicitly disabled for this XMLInputFactory. This could be vulnerable to XML + external entity vulnerabilities. Explicitly disable external entities by setting + "javax.xml.stream.isSupportingExternalEntities" to false. + metadata: + asvs: + control_id: 5.5.2 Insecue XML Deserialization + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v55-deserialization-prevention + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-611: Improper Restriction of XML External Entity Reference' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A04:2017 - XML External Entities (XXE) + - A05:2021 - Security Misconfiguration + - A02:2025 - Security Misconfiguration + references: + - https://semgrep.dev/blog/2022/xml-security-in-java + - https://semgrep.dev/docs/cheat-sheets/java-xxe/ + - https://www.blackhat.com/docs/us-15/materials/us-15-Wang-FileCry-The-New-Age-Of-XXE-java-wp.pdf + - https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#xmlinputfactory-a-stax-parser + semgrep.dev: + rule: + origin: community + r_id: 9164 + rule_id: OrU35O + rv_id: 1263069 + url: + https://semgrep.dev/playground/r/1QTypQZ/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + version_id: 1QTypQZ + shortlink: https://sg.run/XBwA + source: https://semgrep.dev/r/java.lang.security.xmlinputfactory-possible-xxe.xmlinputfactory-possible-xxe + subcategory: + - vuln + technology: + - java + vulnerability_class: + - XML Injection + patterns: + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(\"javax.xml.stream.isSupportingExternalEntities\"\ + , false);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + false);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(\"javax.xml.stream.isSupportingExternalEntities\"\ + , Boolean.FALSE);\n ...\n}\n" + - pattern-not-inside: "$METHOD(...) {\n ...\n $XMLFACTORY.setProperty(javax.xml.stream.XMLInputFactory.IS_SUPPORTING_EXTERNAL_ENTITIES, + Boolean.FALSE);\n ...\n}\n" + - pattern-either: + - pattern: javax.xml.stream.XMLInputFactory.newFactory(...) + - pattern: new XMLInputFactory(...) + severity: WARNING +- id: java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + languages: + - java + message: Using an arbitrary object ('$PARAMTYPE $PARAM') with Java RMI is an insecure deserialization vulnerability. + This object can be manipulated by a malicious actor allowing them to execute code on your system. Instead, use an + integer ID to look up your object, or consider alternative serialization schemes such as JSON. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://frohoff.github.io/appseccali-marshalling-pickles/ + - https://book.hacktricks.xyz/network-services-pentesting/1099-pentesting-java-rmi + - https://youtu.be/t_aw1mDNhzI + - https://github.com/qtc-de/remote-method-guesser + - https://github.com/openjdk/jdk/blob/master/src/java.rmi/share/classes/sun/rmi/server/UnicastRef.java#L303C4-L331 + semgrep.dev: + rule: + origin: community + r_id: 9217 + rule_id: NbUkw5 + rv_id: 1263072 + url: + https://semgrep.dev/playground/r/rxTAKN2/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + version_id: rxTAKN2 + shortlink: https://sg.run/zvnl + source: + https://semgrep.dev/r/java.rmi.security.server-dangerous-object-deserialization.server-dangerous-object-deserialization + subcategory: + - audit + technology: + - rmi + vulnerability_class: + - 'Insecure Deserialization ' + patterns: + - pattern: "interface $INTERFACE extends Remote {\n $RETURNTYPE $METHOD($PARAMTYPE $PARAM) throws RemoteException;\n}\n" + - metavariable-pattern: + language: generic + metavariable: $PARAMTYPE + patterns: + - pattern-not: String + - pattern-not: java.lang.String + - pattern-not: boolean + - pattern-not: Boolean + - pattern-not: java.lang.Boolean + - pattern-not: byte + - pattern-not: Byte + - pattern-not: java.lang.Byte + - pattern-not: char + - pattern-not: Character + - pattern-not: java.lang.Character + - pattern-not: double + - pattern-not: Double + - pattern-not: java.lang.Double + - pattern-not: float + - pattern-not: Float + - pattern-not: java.lang.Float + - pattern-not: int + - pattern-not: Integer + - pattern-not: java.lang.Integer + - pattern-not: long + - pattern-not: Long + - pattern-not: java.lang.Long + - pattern-not: short + - pattern-not: Short + - pattern-not: java.lang.Short + severity: ERROR +- id: java.spring.security.audit.spel-injection.spel-injection + languages: + - java + message: A Spring expression is built with a dynamic value. The source of the value(s) should be verified to avoid + that unfiltered values fall into this risky code evaluation. + metadata: + category: security + confidence: LOW + cwe: + - "CWE-94: Improper Control of Generation of Code ('Code Injection')" + cwe2022-top25: true + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A03:2021 - Injection + - A05:2025 - Injection + references: + - https://owasp.org/Top10/A03_2021-Injection + semgrep.dev: + rule: + origin: community + r_id: 9220 + rule_id: x8Un7b + rv_id: 1263075 + url: https://semgrep.dev/playground/r/kbTzG5Y/java.spring.security.audit.spel-injection.spel-injection + version_id: kbTzG5Y + shortlink: https://sg.run/XBp4 + source: https://semgrep.dev/r/java.spring.security.audit.spel-injection.spel-injection + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPEL_INJECTION + subcategory: + - audit + technology: + - spring + vulnerability_class: + - Code Injection + patterns: + - pattern-either: + - pattern-inside: "class $CLASS {\n ...\n ExpressionParser $PARSER;\n ...\n}\n" + - pattern-inside: "class $CLASS {\n ...\n ExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n ExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern-inside: "class $CLASS {\n ...\n SpelExpressionParser $PARSER;\n ...\n}\n" + - pattern-inside: "class $CLASS {\n ...\n SpelExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n SpelExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern-inside: "class $CLASS {\n ...\n TemplateAwareExpressionParser $PARSER;\n ...\n}\n" + - pattern-inside: "class $CLASS {\n ...\n TemplateAwareExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern-inside: "$X $METHOD(...) {\n ...\n TemplateAwareExpressionParser $PARSER = ...;\n ...\n}\n" + - pattern: "$X $METHOD(...) {\n ...\n $PARSER.parseExpression(...);\n ...\n}\n" + - pattern-not: "$X $METHOD(...) {\n ...\n $PARSER.parseExpression(\"...\");\n ...\n}\n" + - pattern-not: "$X $METHOD(...) {\n ...\n String $S = \"...\";\n ...\n $PARSER.parseExpression($S);\n ...\n}\n" + severity: WARNING +- id: java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + languages: + - java + message: CSRF protection is disabled for this configuration. This is a security risk. + metadata: + asvs: + control_id: 4.2.2 CSRF + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V4-Access-Control.md#v42-operation-level-access-control + section: V4 Access Control + version: '4' + category: security + confidence: LOW + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9221 + rule_id: OrU3gK + rv_id: 1263080 + url: + https://semgrep.dev/playground/r/vdT06dL/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + version_id: vdT06dL + shortlink: https://sg.run/jRnl + source: https://semgrep.dev/r/java.spring.security.audit.spring-csrf-disabled.spring-csrf-disabled + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_PROTECTION_DISABLED + subcategory: + - audit + technology: + - spring + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + pattern: $OBJ.csrf(...).disable(...) + severity: WARNING +- id: java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + languages: + - java + message: Application redirects a user to a destination URL specified by a user supplied parameter that is not + validated. + metadata: + category: security + confidence: MEDIUM + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9223 + rule_id: v8Un7w + rv_id: 1263083 + url: + https://semgrep.dev/playground/r/nWT2Lk0/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + version_id: nWT2Lk0 + shortlink: https://sg.run/9oXz + source: https://semgrep.dev/r/java.spring.security.audit.spring-unvalidated-redirect.spring-unvalidated-redirect + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#UNVALIDATED_REDIRECT + subcategory: + - vuln + technology: + - spring + vulnerability_class: + - Open Redirect + pattern-either: + - pattern: "$X $METHOD(...,String $URL,...) {\n return \"redirect:\" + $URL;\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n String $REDIR = \"redirect:\" + $URL;\n ...\n return $REDIR;\n\ + \ ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n new ModelAndView(\"redirect:\" + $URL);\n ...\n}\n" + - pattern: "$X $METHOD(...,String $URL,...) {\n ...\n String $REDIR = \"redirect:\" + $URL;\n ...\n new ModelAndView($REDIR);\n\ + \ ...\n}" + severity: WARNING +- id: java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + languages: + - java + message: Detected a method annotated with 'RequestMapping' that does not specify the HTTP method. CSRF protections are + not enabled for GET, HEAD, TRACE, or OPTIONS, and by default all HTTP methods are allowed when the HTTP method is + not explicitly specified. This means that a method that performs state changes could be vulnerable to CSRF attacks. + To mitigate, add the 'method' field and specify the HTTP method (such as 'RequestMethod.POST'). + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-352: Cross-Site Request Forgery (CSRF)' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + semgrep.dev: + rule: + origin: community + r_id: 9219 + rule_id: wdUJ7q + rv_id: 1263089 + url: + https://semgrep.dev/playground/r/QkTGq2l/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + version_id: QkTGq2l + shortlink: https://sg.run/2xlq + source: https://semgrep.dev/r/java.spring.security.unrestricted-request-mapping.unrestricted-request-mapping + source-rule-url: https://find-sec-bugs.github.io/bugs.htm#SPRING_CSRF_UNRESTRICTED_REQUEST_MAPPING + subcategory: + - audit + technology: + - spring + vulnerability_class: + - Cross-Site Request Forgery (CSRF) + patterns: + - pattern-inside: "@RequestMapping(...)\n$RETURNTYPE $METHOD(...) { ... }\n" + - pattern-not-inside: "@RequestMapping(..., method = $X, ...)\n$RETURNTYPE $METHOD(...) { ... }\n" + - pattern: "RequestMapping\n" + severity: WARNING +- id: javascript.express.security.audit.possible-user-input-redirect.unknown-value-in-redirect + languages: + - javascript + - typescript + message: It looks like '$UNK' is read from user input and it is used to as a redirect. Ensure '$UNK' is not externally + controlled, otherwise this is an open redirect. + metadata: + asvs: + control_id: 5.5.1 Insecue Redirect + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x13-V5-Validation-Sanitization-Encoding.md#v51-input-validation + section: V5 Validation, Sanitization and Encoding + version: '4' + category: security + confidence: LOW + cwe: + - "CWE-601: URL Redirection to Untrusted Site ('Open Redirect')" + impact: LOW + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A01:2021 - Broken Access Control + - A01:2025 - Broken Access Control + references: + - https://owasp.org/Top10/A01_2021-Broken_Access_Control + semgrep.dev: + rule: + origin: community + r_id: 9275 + rule_id: gxU12X + rv_id: 1263147 + url: + https://semgrep.dev/playground/r/3ZT4Xev/javascript.express.security.audit.possible-user-input-redirect.unknown-value-in-redirect + version_id: 3ZT4Xev + shortlink: https://sg.run/OPv2 + source: + https://semgrep.dev/r/javascript.express.security.audit.possible-user-input-redirect.unknown-value-in-redirect + subcategory: + - audit + technology: + - express + vulnerability_class: + - Open Redirect + patterns: + - pattern-either: + - pattern-inside: "$UNK = query.$B;\n...\n" + - pattern-inside: "$UNK = $A.query.$B;\n...\n" + - pattern-inside: "$UNK = req.$SOMETHING;\n...\n" + - pattern: $RES.redirect(..., <... $UNK ...>, ...) + severity: WARNING +- id: javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + languages: + - javascript + - typescript + message: Found an insecure gRPC connection. This creates a connection without encryption to a gRPC client/server. A + malicious attacker could tamper with the gRPC message, which could compromise the machine. + metadata: + category: security + confidence: LOW + cwe: + - 'CWE-502: Deserialization of Untrusted Data' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: LOW + owasp: + - A08:2017 - Insecure Deserialization + - A08:2021 - Software and Data Integrity Failures + - A08:2025 - Software or Data Integrity Failures + references: + - https://blog.gopheracademy.com/advent-2017/go-grpc-beyond-basics/#:~:text=disables%20transport%20security + semgrep.dev: + rule: + origin: community + r_id: 9291 + rule_id: lBU9D8 + rv_id: 1263180 + url: + https://semgrep.dev/playground/r/e1TyjAl/javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + version_id: e1TyjAl + shortlink: https://sg.run/5QkD + source: + https://semgrep.dev/r/javascript.grpc.security.grpc-nodejs-insecure-connection.grpc-nodejs-insecure-connection + subcategory: + - audit + technology: + - grpc + vulnerability_class: + - 'Insecure Deserialization ' + pattern-either: + - pattern: "require('grpc');\n...\n$GRPC($ADDR,...,$CREDENTIALS.createInsecure(),...);\n" + - pattern: "require('grpc');\n...\nnew $GRPC($ADDR,...,$CREDENTIALS.createInsecure(),...);\n" + - pattern: "require('grpc');\n...\n$CREDS = <... $CREDENTIALS.createInsecure() ...>;\n...\n$GRPC($ADDR,...,$CREDS,...);" + - pattern: "require('grpc');\n...\n$CREDS = <... $CREDENTIALS.createInsecure() ...>;\n...\nnew $GRPC($ADDR,...,$CREDS,...);" + severity: ERROR +- id: javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + interfile: true + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9293 + rule_id: JDUyRl + rv_id: 1263182 + url: https://semgrep.dev/playground/r/d6TyxbX/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + version_id: d6TyxbX + shortlink: https://sg.run/Ro1g + source: https://semgrep.dev/r/javascript.jose.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jose + - jwt + - secrets + vulnerability_class: + - Hard-coded Secrets + options: + interfile: true + symbolic_propagation: true + patterns: + - pattern-inside: "$JOSE = require(\"jose\");\n...\n" + - pattern-either: + - pattern-inside: "var {JWT} = $JOSE;\n...\n" + - pattern-inside: "var {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWT} = $JOSE;\n...\n" + - pattern-inside: "const {JWK, JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWT} = $JOSE;\n...\n" + - pattern-inside: "let {JWK, JWT} = $JOSE;\n...\n" + - pattern-either: + - pattern: "JWT.verify($P, \"...\", ...);\n" + - pattern: "JWT.sign($P, \"...\", ...);\n" + - pattern: "JWT.verify($P, JWK.asKey(\"...\"), ...); \n" + - pattern: "$JWT.sign($P, JWK.asKey(\"...\"), ...);\n" + severity: WARNING +- id: javascript.jose.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9294 + rule_id: 5rUOGN + rv_id: 1263183 + url: https://semgrep.dev/playground/r/ZRTKAyb/javascript.jose.security.jwt-none-alg.jwt-none-alg + version_id: ZRTKAyb + shortlink: https://sg.run/AvRL + source: https://semgrep.dev/r/javascript.jose.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jose + - jwt + vulnerability_class: + - Cryptographic Issues + pattern-either: + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nvar $T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\n$T = JWT.verify($P, JWK.None,...);\n" + - pattern: "var $JOSE = require(\"jose\");\n...\nvar { JWK, JWT } = $JOSE;\n...\nJWT.verify($P, JWK.None,...);\n" + severity: ERROR +- id: javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + languages: + - javascript + - typescript + message: A hard-coded credential was detected. It is not recommended to store credentials in source-code, as this + risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use + environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware + Security Module). + metadata: + asvs: + control_id: 3.5.2 Static API keys or secret + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: HIGH + cwe: + - 'CWE-798: Use of Hard-coded Credentials' + cwe2021-top25: true + cwe2022-top25: true + impact: MEDIUM + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: HIGH + owasp: + - A07:2021 - Identification and Authentication Failures + - A07:2025 - Authentication Failures + references: + - https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html + semgrep.dev: + rule: + origin: community + r_id: 9300 + rule_id: WAUon7 + rv_id: 1263189 + url: https://semgrep.dev/playground/r/gETB75D/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + version_id: gETB75D + shortlink: https://sg.run/4xN9 + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-hardcode.hardcoded-jwt-secret + subcategory: + - vuln + technology: + - jwt + - javascript + - secrets + vulnerability_class: + - Hard-coded Secrets + mode: taint + pattern-sinks: + - patterns: + - pattern-either: + - pattern-inside: "$JWT = require(\"jsonwebtoken\")\n...\n" + - pattern-inside: "import $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import * as $JWT from \"jsonwebtoken\"\n...\n" + - pattern-inside: "import {...,$JWT,...} from \"jsonwebtoken\"\n...\n" + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,$VALUE,...);\n" + - pattern-inside: "$JWT.verify($DATA,$VALUE,...);\n" + - focus-metavariable: $VALUE + pattern-sources: + - patterns: + - pattern: "$X = '...' \n" + - pattern: "$X = '$Y' \n" + - patterns: + - pattern-either: + - pattern-inside: "$JWT.sign($DATA,\"...\",...);\n" + - pattern-inside: "$JWT.verify($DATA,\"...\",...);\n" + severity: WARNING +- id: javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + languages: + - javascript + - typescript + message: Detected use of the 'none' algorithm in a JWT token. The 'none' algorithm assumes the integrity of the token + has already been verified. This would allow a malicious actor to forge a JWT token that will automatically be + verified. Do not explicitly use the 'none' algorithm. Instead, use an algorithm such as 'HS256'. + metadata: + asvs: + control_id: 3.5.3 Insecue Stateless Session Tokens + control_url: + https://github.com/OWASP/ASVS/blob/master/4.0/en/0x12-V3-Session-management.md#v35-token-based-session-management + section: 'V3: Session Management Verification Requirements' + version: '4' + category: security + confidence: MEDIUM + cwe: + - 'CWE-327: Use of a Broken or Risky Cryptographic Algorithm' + impact: HIGH + license: Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license + likelihood: MEDIUM + owasp: + - A03:2017 - Sensitive Data Exposure + - A02:2021 - Cryptographic Failures + - A04:2025 - Cryptographic Failures + references: + - https://owasp.org/Top10/A02_2021-Cryptographic_Failures + semgrep.dev: + rule: + origin: community + r_id: 9301 + rule_id: 0oU53g + rv_id: 1263190 + url: https://semgrep.dev/playground/r/QkTGqQo/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + version_id: QkTGqQo + shortlink: https://sg.run/PJXv + source: https://semgrep.dev/r/javascript.jsonwebtoken.security.jwt-none-alg.jwt-none-alg + source-rule-url: https://semgrep.dev/blog/2020/hardcoded-secrets-unverified-tokens-and-other-common-jwt-mistakes/ + subcategory: + - vuln + technology: + - jwt + vulnerability_class: + - Cryptographic Issues + patterns: + - pattern-inside: "$JWT = require(\"jsonwebtoken\");\n...\n" + - pattern: $JWT.verify($P, $X, {algorithms:[...,'none',...]},...) + severity: ERROR +- id: javascript.lang.security.audit.unknown-value-with-script-tag.unknown-value-with-script-tag + languages: + - javascript + - typescript + message: Cannot determine what '$UNK' is and it is used with a '