Skip to content

g1t/crates/scan/fixtures/semgrep.sarif

427 lines26,282 bytesCodeBlame
1{
2 "version": "2.1.0",
3 "runs": [
4 {
5 "invocations": [
6 {
7 "executionSuccessful": true,
8 "toolExecutionNotifications": []
9 }
10 ],
11 "results": [
12 {
13 "fingerprints": {
14 "matchBasedId/v1": "requires login"
15 },
16 "locations": [
17 {
18 "physicalLocation": {
19 "artifactLocation": {
20 "uri": "src/server.js",
21 "uriBaseId": "%SRCROOT%"
22 },
23 "region": {
24 "endColumn": 22,
25 "endLine": 3,
26 "snippet": {
27 "text": "const app = express();"
28 },
29 "startColumn": 7,
30 "startLine": 3
31 }
32 }
33 }
34 ],
35 "message": {
36 "text": "A CSRF middleware was not detected in your express application. Ensure you are either using one such as `csurf` or `csrf` (see rule references) and/or you are properly doing CSRF validation in your routes with a token or cookies."
37 },
38 "properties": {},
39 "ruleId": "javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage"
40 },
41 {
42 "fingerprints": {
43 "matchBasedId/v1": "requires login"
44 },
45 "locations": [
46 {
47 "physicalLocation": {
48 "artifactLocation": {
49 "uri": "src/server.js",
50 "uriBaseId": "%SRCROOT%"
51 },
52 "region": {
53 "endColumn": 29,
54 "endLine": 6,
55 "snippet": {
56 "text": " exec('ls ' + req.query.dir, (err, out) => res.send(out));"
57 },
58 "startColumn": 8,
59 "startLine": 6
60 }
61 }
62 }
63 ],
64 "message": {
65 "text": "Detected calls to child_process from a function argument `req`. This could lead to a command injection if the input is user controllable. Try to avoid calls to child_process, and if it is needed ensure user input is correctly sanitized or sandboxed. "
66 },
67 "properties": {},
68 "ruleId": "javascript.lang.security.detect-child-process.detect-child-process"
69 },
70 {
71 "fingerprints": {
72 "matchBasedId/v1": "requires login"
73 },
74 "locations": [
75 {
76 "physicalLocation": {
77 "artifactLocation": {
78 "uri": "src/server.js",
79 "uriBaseId": "%SRCROOT%"
80 },
81 "region": {
82 "endColumn": 32,
83 "endLine": 10,
84 "snippet": {
85 "text": " res.send(eval(req.query.code));"
86 },
87 "startColumn": 12,
88 "startLine": 10
89 }
90 }
91 }
92 ],
93 "message": {
94 "text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources."
95 },
96 "properties": {},
97 "ruleId": "javascript.browser.security.eval-detected.eval-detected"
98 },
99 {
100 "fingerprints": {
101 "matchBasedId/v1": "requires login"
102 },
103 "locations": [
104 {
105 "physicalLocation": {
106 "artifactLocation": {
107 "uri": "src/server.js",
108 "uriBaseId": "%SRCROOT%"
109 },
110 "region": {
111 "endColumn": 32,
112 "endLine": 10,
113 "snippet": {
114 "text": " res.send(eval(req.query.code));"
115 },
116 "startColumn": 12,
117 "startLine": 10
118 }
119 }
120 }
121 ],
122 "message": {
123 "text": "Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML."
124 },
125 "properties": {},
126 "ruleId": "javascript.express.security.audit.xss.direct-response-write.direct-response-write"
127 },
128 {
129 "fingerprints": {
130 "matchBasedId/v1": "requires login"
131 },
132 "locations": [
133 {
134 "physicalLocation": {
135 "artifactLocation": {
136 "uri": "src/server.js",
137 "uriBaseId": "%SRCROOT%"
138 },
139 "region": {
140 "endColumn": 32,
141 "endLine": 10,
142 "snippet": {
143 "text": " res.send(eval(req.query.code));"
144 },
145 "startColumn": 12,
146 "startLine": 10
147 }
148 }
149 }
150 ],
151 "message": {
152 "text": "Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible."
153 },
154 "properties": {},
155 "ruleId": "javascript.lang.security.audit.code-string-concat.code-string-concat"
156 },
157 {
158 "fingerprints": {
159 "matchBasedId/v1": "requires login"
160 },
161 "locations": [
162 {
163 "physicalLocation": {
164 "artifactLocation": {
165 "uri": "src/tool.py",
166 "uriBaseId": "%SRCROOT%"
167 },
168 "region": {
169 "endColumn": 43,
170 "endLine": 5,
171 "snippet": {
172 "text": " return subprocess.call(cmd, shell=True)"
173 },
174 "startColumn": 39,
175 "startLine": 5
176 }
177 }
178 }
179 ],
180 "message": {
181 "text": "Found 'subprocess' function 'call' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."
182 },
183 "properties": {},
184 "ruleId": "python.lang.security.audit.subprocess-shell-true.subprocess-shell-true"
185 },
186 {
187 "fingerprints": {
188 "matchBasedId/v1": "requires login"
189 },
190 "locations": [
191 {
192 "physicalLocation": {
193 "artifactLocation": {
194 "uri": "src/tool.py",
195 "uriBaseId": "%SRCROOT%"
196 },
197 "region": {
198 "endColumn": 30,
199 "endLine": 8,
200 "snippet": {
201 "text": " return pickle.loads(data)"
202 },
203 "startColumn": 12,
204 "startLine": 8
205 }
206 }
207 }
208 ],
209 "message": {
210 "text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format."
211 },
212 "properties": {},
213 "ruleId": "python.lang.security.deserialization.pickle.avoid-pickle"
214 }
215 ],
216 "tool": {
217 "driver": {
218 "name": "Semgrep OSS",
219 "rules": [
220 {
221 "defaultConfiguration": {
222 "level": "warning"
223 },
224 "fullDescription": {
225 "text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources."
226 },
227 "help": {
228 "markdown": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/javascript.browser.security.eval-detected.eval-detected)\n - [https://owasp.org/Top10/A03_2021-Injection](https://owasp.org/Top10/A03_2021-Injection)\n",
229 "text": "Detected the use of eval(). eval() can be dangerous if used to evaluate dynamic content. If this content can be input from outside the program, this may be a code injection vulnerability. Ensure evaluated content is not definable by external sources.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
230 },
231 "helpUri": "https://semgrep.dev/r/javascript.browser.security.eval-detected.eval-detected",
232 "id": "javascript.browser.security.eval-detected.eval-detected",
233 "name": "javascript.browser.security.eval-detected.eval-detected",
234 "properties": {
235 "precision": "very-high",
236 "tags": [
237 "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
238 "LOW CONFIDENCE",
239 "OWASP-A03:2021 - Injection",
240 "OWASP-A05:2025 - Injection",
241 "security"
242 ]
243 },
244 "shortDescription": {
245 "text": "Semgrep Finding: javascript.browser.security.eval-detected.eval-detected"
246 }
247 },
248 {
249 "defaultConfiguration": {
250 "level": "note"
251 },
252 "fullDescription": {
253 "text": "A CSRF middleware was not detected in your express application. Ensure you are either using one such as `csurf` or `csrf` (see rule references) and/or you are properly doing CSRF validation in your routes with a token or cookies."
254 },
255 "help": {
256 "markdown": "A CSRF middleware was not detected in your express application. Ensure you are either using one such as `csurf` or `csrf` (see rule references) and/or you are properly doing CSRF validation in your routes with a token or cookies.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage)\n - [https://www.npmjs.com/package/csurf](https://www.npmjs.com/package/csurf)\n - [https://www.npmjs.com/package/csrf](https://www.npmjs.com/package/csrf)\n - [https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html](https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html)\n",
257 "text": "A CSRF middleware was not detected in your express application. Ensure you are either using one such as `csurf` or `csrf` (see rule references) and/or you are properly doing CSRF validation in your routes with a token or cookies.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
258 },
259 "helpUri": "https://semgrep.dev/r/javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage",
260 "id": "javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage",
261 "name": "javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage",
262 "properties": {
263 "precision": "very-high",
264 "tags": [
265 "CWE-352: Cross-Site Request Forgery (CSRF)",
266 "LOW CONFIDENCE",
267 "OWASP-A01:2021 - Broken Access Control",
268 "OWASP-A01:2025 - Broken Access Control",
269 "security"
270 ]
271 },
272 "shortDescription": {
273 "text": "Semgrep Finding: javascript.express.security.audit.express-check-csurf-middleware-usage.express-check-csurf-middleware-usage"
274 }
275 },
276 {
277 "defaultConfiguration": {
278 "level": "warning"
279 },
280 "fullDescription": {
281 "text": "Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML."
282 },
283 "help": {
284 "markdown": "Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write)\n - [https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html](https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html)\n",
285 "text": "Detected directly writing to a Response object from user-defined input. This bypasses any HTML escaping and may expose your application to a Cross-Site-scripting (XSS) vulnerability. Instead, use 'resp.render()' to render safely escaped HTML.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
286 },
287 "helpUri": "https://semgrep.dev/r/javascript.express.security.audit.xss.direct-response-write.direct-response-write",
288 "id": "javascript.express.security.audit.xss.direct-response-write.direct-response-write",
289 "name": "javascript.express.security.audit.xss.direct-response-write.direct-response-write",
290 "properties": {
291 "precision": "very-high",
292 "tags": [
293 "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
294 "MEDIUM CONFIDENCE",
295 "OWASP-A03:2021 - Injection",
296 "OWASP-A05:2025 - Injection",
297 "OWASP-A07:2017 - Cross-Site Scripting (XSS)",
298 "security"
299 ]
300 },
301 "shortDescription": {
302 "text": "Semgrep Finding: javascript.express.security.audit.xss.direct-response-write.direct-response-write"
303 }
304 },
305 {
306 "defaultConfiguration": {
307 "level": "error"
308 },
309 "fullDescription": {
310 "text": "Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible."
311 },
312 "help": {
313 "markdown": "Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat)\n - [https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval)\n - [https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback](https://nodejs.org/api/child_process.html#child_processexeccommand-options-callback)\n - [https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/](https://www.stackhawk.com/blog/nodejs-command-injection-examples-and-prevention/)\n - [https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html](https://ckarande.gitbooks.io/owasp-nodegoat-tutorial/content/tutorial/a1_-_server_side_js_injection.html)\n",
314 "text": "Found data from an Express or Next web request flowing to `eval`. If this data is user-controllable this can lead to execution of arbitrary system commands in the context of your application process. Avoid `eval` whenever possible.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
315 },
316 "helpUri": "https://semgrep.dev/r/javascript.lang.security.audit.code-string-concat.code-string-concat",
317 "id": "javascript.lang.security.audit.code-string-concat.code-string-concat",
318 "name": "javascript.lang.security.audit.code-string-concat.code-string-concat",
319 "properties": {
320 "precision": "very-high",
321 "tags": [
322 "CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')",
323 "HIGH CONFIDENCE",
324 "OWASP-A03:2021 - Injection",
325 "OWASP-A05:2025 - Injection",
326 "security"
327 ]
328 },
329 "shortDescription": {
330 "text": "Semgrep Finding: javascript.lang.security.audit.code-string-concat.code-string-concat"
331 }
332 },
333 {
334 "defaultConfiguration": {
335 "level": "error"
336 },
337 "fullDescription": {
338 "text": "Detected calls to child_process from a function argument `$FUNC`. This could lead to a command injection if the input is user controllable. Try to avoid calls to child_process, and if it is needed ensure user input is correctly sanitized or sandboxed. "
339 },
340 "help": {
341 "markdown": "Detected calls to child_process from a function argument `$FUNC`. This could lead to a command injection if the input is user controllable. Try to avoid calls to child_process, and if it is needed ensure user input is correctly sanitized or sandboxed. \n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/javascript.lang.security.detect-child-process.detect-child-process)\n - [https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html#do-not-use-dangerous-functions](https://cheatsheetseries.owasp.org/cheatsheets/Nodejs_Security_Cheat_Sheet.html#do-not-use-dangerous-functions)\n",
342 "text": "Detected calls to child_process from a function argument `$FUNC`. This could lead to a command injection if the input is user controllable. Try to avoid calls to child_process, and if it is needed ensure user input is correctly sanitized or sandboxed. \n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
343 },
344 "helpUri": "https://semgrep.dev/r/javascript.lang.security.detect-child-process.detect-child-process",
345 "id": "javascript.lang.security.detect-child-process.detect-child-process",
346 "name": "javascript.lang.security.detect-child-process.detect-child-process",
347 "properties": {
348 "precision": "very-high",
349 "tags": [
350 "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
351 "LOW CONFIDENCE",
352 "OWASP-A01:2017 - Injection",
353 "OWASP-A03:2021 - Injection",
354 "OWASP-A05:2025 - Injection",
355 "security"
356 ]
357 },
358 "shortDescription": {
359 "text": "Semgrep Finding: javascript.lang.security.detect-child-process.detect-child-process"
360 }
361 },
362 {
363 "defaultConfiguration": {
364 "level": "error"
365 },
366 "fullDescription": {
367 "text": "Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead."
368 },
369 "help": {
370 "markdown": "Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true)\n - [https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess](https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess)\n - [https://docs.python.org/3/library/subprocess.html](https://docs.python.org/3/library/subprocess.html)\n",
371 "text": "Found 'subprocess' function '$FUNC' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
372 },
373 "helpUri": "https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true",
374 "id": "python.lang.security.audit.subprocess-shell-true.subprocess-shell-true",
375 "name": "python.lang.security.audit.subprocess-shell-true.subprocess-shell-true",
376 "properties": {
377 "precision": "very-high",
378 "tags": [
379 "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
380 "MEDIUM CONFIDENCE",
381 "OWASP-A01:2017 - Injection",
382 "OWASP-A03:2021 - Injection",
383 "OWASP-A05:2025 - Injection",
384 "security"
385 ]
386 },
387 "shortDescription": {
388 "text": "Semgrep Finding: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true"
389 }
390 },
391 {
392 "defaultConfiguration": {
393 "level": "warning"
394 },
395 "fullDescription": {
396 "text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format."
397 },
398 "help": {
399 "markdown": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n\n#### 💎 Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-pickle)\n - [https://docs.python.org/3/library/pickle.html](https://docs.python.org/3/library/pickle.html)\n",
400 "text": "Avoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.\n💎 Enable cross-file analysis and Pro rules for free at sg.run/pro"
401 },
402 "helpUri": "https://semgrep.dev/r/python.lang.security.deserialization.pickle.avoid-pickle",
403 "id": "python.lang.security.deserialization.pickle.avoid-pickle",
404 "name": "python.lang.security.deserialization.pickle.avoid-pickle",
405 "properties": {
406 "precision": "very-high",
407 "tags": [
408 "CWE-502: Deserialization of Untrusted Data",
409 "LOW CONFIDENCE",
410 "OWASP-A08:2017 - Insecure Deserialization",
411 "OWASP-A08:2021 - Software and Data Integrity Failures",
412 "OWASP-A08:2025 - Software or Data Integrity Failures",
413 "security"
414 ]
415 },
416 "shortDescription": {
417 "text": "Semgrep Finding: python.lang.security.deserialization.pickle.avoid-pickle"
418 }
419 }
420 ],
421 "semanticVersion": "1.179.0"
422 }
423 }
424 }
425 ],
426 "$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json"
427}